Who Are You?, I Cannot Let You In
Figure out how Linux decides who gets in and what they can do once inside: users, groups, sudo, and rwx permissions.
Who Is on This Machine?
Linux was built as a multi-user system. Many people (and many services) can be logged in at once, so the OS needs a way to keep them out of each other’s stuff. That’s the whole job of users, groups, and permissions.
There are three kinds of accounts you’ll run into:
| Type | UID (usually) | Notes |
|---|---|---|
| root | 0 | The superuser. Can do anything, no questions asked. |
| System users | 1 to 999 | Created for services like www-data or postfix. They normally can’t log in (/usr/sbin/nologin). |
| Regular users | 1000 and up | Real people. These are the accounts you create. |
Account info lives in three plain text files:
| File | Contains |
|---|---|
/etc/passwd | One line per user: name, UID, GID, home, shell |
/etc/shadow | The password hashes (readable by root only) |
/etc/group | One line per group and its members |
Here is one line from /etc/passwd, split by colons:
1
alice:x:1001:1001:Alice:/home/alice:/bin/bash
| Field | Value | Meaning |
|---|---|---|
| 1 | alice | Username |
| 2 | x | Password placeholder, the real hash is in /etc/shadow |
| 3 | 1001 | UID |
| 4 | 1001 | GID of the primary group |
| 5 | Alice | Comment / full name |
| 6 | /home/alice | Home directory |
| 7 | /bin/bash | Login shell |
1
2
3
4
5
6
7
# Who am I, and what groups do I have?
whoami
id
# Look up another user
id alice
getent passwd alice
Managing Users
| Command | What it does |
|---|---|
sudo adduser alice | Friendly wrapper on Debian/Ubuntu. Asks questions, creates the home directory and a group with the same name. |
sudo useradd -m -s /bin/bash alice | The low-level, works-everywhere version. Forget -m and you may end up with no home directory. |
sudo passwd alice | Set or change a password (run passwd alone to change your own). |
sudo usermod -s /bin/zsh alice | Modify an existing account (shell, home, groups, and more). |
sudo passwd -l alice | Lock an account without deleting it. |
sudo userdel alice | Delete the account only. The home directory stays behind. |
sudo userdel -r alice | Delete the account and its home directory. |
Good to know: on Debian/Ubuntu use
adduser, on RHEL/Rocky useuseradd. Both end up in the same files, they just ask different amounts of questions.
Groups
A group is simply a named list of users. Instead of giving access to five people one by one, you give it to a group once and then move people in and out.
- Primary group: the one stored in
/etc/passwd. Every user has exactly one, and every new file they create is tagged with it. - Secondary groups: extras you add later. A user can have none, one, or many.
| Command | What it does |
|---|---|
groups alice | Show all groups for a user |
id alice | Same, but with the numeric IDs too |
sudo groupadd webteam | Create a group |
sudo usermod -aG webteam alice | Add alice to a secondary group |
sudo gpasswd -d alice webteam | Remove alice from a group |
sudo groupdel webteam | Delete a group |
newgrp webteam | Start a shell that uses webteam as the active group |
Watch out:
usermod -Gwithout-areplaces all secondary groups. It’s an easy way to accidentally remove yourself fromsudo. Always type-aG.
Group changes don’t reach sessions that are already open. Log out and back in (or use
newgrp) before testing.
Sudo, Not Root
Doing everything as a root all day is risky. One typo and there’s no safety net. The usual approach is to work as a normal user and use admin power only when you need it, with sudo.
1
2
sudo apt update # one command as root
sudo -l # list what you're allowed to run
Who gets to use sudo is decided by group membership:
| Distro family | Admin group |
|---|---|
| Debian / Ubuntu | sudo |
| RHEL / Rocky / Fedora | wheel |
1
2
sudo usermod -aG sudo alice # Debian/Ubuntu
sudo usermod -aG wheel alice # RHEL family
For finer rules, edit the sudoers file, only with visudo. It checks the syntax before saving, so a typo can’t lock you out.
1
sudo visudo -f /etc/sudoers.d/alice
1
2
# alice may restart nginx and nothing else
alice ALL=(ALL) /usr/bin/systemctl restart nginx
Best practice: give people the smallest set of commands they need (least privilege), and use full paths in sudoers (
which systemctltells you the path).
Reading Permissions
Run ls -l and look at the first column:
1
-rwxr-xr-- 1 alice webteam 220 Oct 4 10:00 deploy.sh
| Chars | - | rwx | r-x | r-- |
|---|---|---|---|---|
| Meaning | Type (- file, d directory, l link) | Owner (alice) | Group (webteam) | Others (everyone else) |
Then comes the link count, owner, group, size, date, and name.
The same three letters mean different things on files and directories:
| File | Directory | |
|---|---|---|
r read | View the contents | List the names inside |
w write | Change the contents | Create, rename, or delete entries inside (needs x too) |
x execute | Run it as a program | Enter it with cd and reach what’s inside |
Changing Permissions
chmod
You can describe the change with letters or with numbers.
1
2
3
4
5
6
7
# Letters: who (u g o a) + operator (+ - =) + permission (r w x)
chmod u+x deploy.sh # let the owner run it
chmod g+w,o-rwx notes.txt # group can write, others get nothing
chmod -R g+rX project/ # recursive; capital X only adds x on directories
# Numbers (octal)
chmod 640 notes.txt
For the numeric style, each permission has a value, and you add them per column:
| Permission | Value |
|---|---|
r | 4 |
w | 2 |
x | 1 |
So rwx = 4+2+1 = 7, r-x = 4+1 = 5, rw- = 4+2 = 6, r-- = 4.
| Mode | Looks like | Typical use |
|---|---|---|
644 | rw-r--r-- | Normal files |
755 | rwxr-xr-x | Scripts, public directories |
600 | rw------- | Private files like SSH keys |
640 | rw-r----- | Configs the group may read |
770 | rwxrwx--- | Shared team folder |
Don’t reach for
777. It means every user on the box can change the file. If something “needs 777 to work”, the real fix is almost always the right owner or group.
chown and chgrp
1
2
3
4
sudo chown alice file.txt # change owner
sudo chown alice:webteam file.txt # owner and group together
sudo chown -R alice:webteam /srv/site # whole tree
sudo chgrp webteam file.txt # group only
umask: Default Permissions
Brand new file is 644 and a new folder is 755, without you ever running chmod? That’s the umask at work.
Think of it as a list of things to take away from every new file or folder. Linux starts with the maximum, then the umask crosses permissions out.
| New item | Starts as |
|---|---|
| File | 666 (rw-rw-rw-), files never start with x |
| Directory | 777 (rwxrwxrwx) |
The most common umask is 022. Read it as three digits, one each for owner, group, and others. A 2 means “remove write”.
| Owner | Group | Others | |
|---|---|---|---|
umask 022 | remove nothing | remove w | remove w |
| New file | rw- | r-- | r-- |
| New directory | rwx | r-x | r-x |
That gives you 644 for files and 755 for directories.
For the usual umask values, a quick shortcut works: subtract the umask from the starting mode. File: 666 - 022 = 644. Directory: 777 - 022 = 755.
| umask | Files | Directories | Use it when |
|---|---|---|---|
022 | 644 | 755 | Default. Others can look but not touch |
002 | 664 | 775 | Team folders where the group edits together |
077 | 600 | 700 | Private. Only the owner gets in |
1
2
umask # show the current value
umask 002 # change it for this terminal session only
The umask only affects files created after you set it. Existing files keep their permissions, and closing the terminal resets it. To keep it, add the
umaskline to~/.bashrc.
Special Bits
Three extra flags that show up in multi-user setups:
| Bit | Set with | On a file | On a directory |
|---|---|---|---|
| setuid | chmod u+s (4xxx) | Runs with the owner’s rights (that’s how passwd can edit /etc/shadow) | Ignored |
| setgid | chmod g+s (2xxx) | Runs with the group’s rights | New files inherit the directory’s group |
| sticky | chmod +t (1xxx) | Ignored | Only the file’s owner (or root) can delete or rename it |
You’ve already seen the sticky bit: ls -ld /tmp shows drwxrwxrwt. Everybody can write there, but you can’t delete someone else’s files.
setuid on your own scripts is a security risk. Leave it to system tools unless you really know why you need it.
Good Habits
| Do this | Because |
|---|---|
| One account per person | Files stay separated and logs show who did what |
| Never share passwords | Shared logins can’t be audited or revoked cleanly |
| Use groups for teamwork | One change to the group, instead of editing every file |
Use sudo instead of root | Fewer mistakes, better logging |
| Give the least access needed | A compromised account can only do so much |
Review with ls -l and id | Check before you assume |
Key Commands Cheat Sheet
| Command | What it does |
|---|---|
id, whoami, groups | Who am I and what groups do I belong to |
adduser, useradd -m, userdel -r | Create or remove a user |
passwd | Set a password |
groupadd, usermod -aG, gpasswd -d | Create a group, add or remove members |
sudo, visudo | Run as admin, safely edit sudo rules |
ls -l, ls -ld | Read permissions (use -d for a directory itself) |
chmod, chown, chgrp | Change permissions, owner, group |
getent passwd, getent group | Look up accounts and groups |
Hands-On Case
Scenario: A small web team (Alice and Bob) needs one shared folder at /srv/webteam. They should both be able to edit each other’s files. Carol works in another department and must stay out.
Try it yourself first, then open the solution to check.
Goal:
- Create the group
webteamand the usersalice,bob,carol - Put only Alice and Bob in the group
- Make
/srv/webteamowned byroot:webteam, with group-shared files and no access for others - Prove it works for Alice and Bob, and fails for Carol
Show solution
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
# 1. Create the group and the users
sudo groupadd webteam
sudo useradd -m -s /bin/bash alice
sudo useradd -m -s /bin/bash bob
sudo useradd -m -s /bin/bash carol
# 2. Add Alice and Bob (Carol stays out)
sudo usermod -aG webteam alice
sudo usermod -aG webteam bob
# 3. Build the shared directory
sudo mkdir /srv/webteam
sudo chown root:webteam /srv/webteam
sudo chmod 2770 /srv/webteam
# 4. Check the setup
ls -ld /srv/webteam # drwxrws--- (the "s" is the setgid bit)
id alice
id bob
1
2
3
4
5
6
7
8
9
# 5. Test it, one user at a time
# --- Alice creates a file ---
sudo su - alice # switch to Alice
whoami # should print: alice
umask 002 # let the group edit new files
echo "<h1>Hello</h1>" > /srv/webteam/index.html
ls -l /srv/webteam # group is webteam, even though Alice's primary group is alice
exit # go back to your own user
1
2
3
4
5
6
# --- Bob edits the same file ---
sudo su - bob # switch to Bob
whoami # should print: bob
echo "<p>Bob was here</p>" >> /srv/webteam/index.html
cat /srv/webteam/index.html # you should see both lines
exit
1
2
3
4
5
# --- Carol tries to peek ---
sudo su - carol # switch to Carol
whoami # should print: carol
ls /srv/webteam # Permission denied
exit
Command Explanation
| Part | What it does |
|---|---|
useradd -m -s /bin/bash | Create the user with a home directory and a bash shell |
usermod -aG webteam | Append the group, don’t overwrite existing ones |
chown root:webteam | Root owns the folder, the team group controls it |
chmod 2770 | 2 = setgid, then rwx owner, rwx group, --- others |
sudo -u alice | Run the command as Alice without needing her password |
umask 002 | Make new files group-writable (see the note below) |
Why the
umask 002? The default umask022creates files as644, so the group could read Alice’s file but not edit it. Setting002gives new files664. In real setups you’d put this in the users’ shell profile.
1
2
3
4
5
6
# cleanup
sudo userdel -r alice
sudo userdel -r bob
sudo userdel -r carol
sudo groupdel webteam
sudo rm -rf /srv/webteam
Going further: add the sticky bit (
chmod 3770 /srv/webteam) so Bob can edit Alice’s files but can’t delete them.
Glossary
| Term | Detail |
|---|---|
| UID | Numeric ID of a user. root is always 0 |
| GID | Numeric ID of a group |
| Primary group | The one group stored in /etc/passwd; new files get tagged with it |
| Secondary group | Any extra group a user is added to |
| sudo | Tool that runs one command with elevated privileges |
| Octal mode | Permissions written as numbers (4=r, 2=w, 1=x), like 750 |
| setgid | Bit that makes new files in a directory inherit its group |
| Sticky bit | Bit that stops users from deleting each other’s files in a shared directory |
| umask | The default “subtract these permissions” mask applied to new files |
Finish
Thanks for following along. Before moving on, run through the post-test below and see how far you’ve come.
