Module 5 · Users, groups and permissions
/etc/passwd, /etc/group and /etc/shadow
The three text files where users, groups and passwords live, field by field, and how to read them with the tools you already know.
What you will learn
- Name the seven fields of a `/etc/passwd` line and the four of `/etc/group`.
- Explain why passwords moved to `/etc/shadow` and what `!`, `*` and an empty field mean there.
- Extract users and fields with `grep`, `cut` and `awk`.
A database made of text
Unix keeps its user database in plain text files, one record per line, fields separated by colons. There is no daemon to query and no binary format: cat is enough to read them and any editor can change them. Three files matter: /etc/passwd for users, /etc/group for groups and /etc/shadow for the password hashes. Everything id, ls -l and su know about names comes from here.
/etc/passwd: seven fields
~% cat /etc/passwd
root:x:0:0:root:/root:/bin/sh
daemon:x:1:1:daemon:/usr/sbin:/bin/false
bin:x:2:2:bin:/bin:/bin/false
sys:x:3:3:sys:/dev:/bin/false
sync:x:4:100:sync:/bin:/bin/sync
mail:x:8:8:mail:/var/spool/mail:/bin/false
www-data:x:33:33:www-data:/var/www:/bin/false
operator:x:37:37:Operator:/var:/bin/false
nobody:x:65534:65534:nobody:/home:/bin/false
| # | Field | In `root:x:0:0:root:/root:/bin/sh` |
|---|---|---|
| 1 | Login name | root |
| 2 | Password; x means "look in /etc/shadow" | x |
| 3 | UID | 0 |
| 4 | Primary GID | 0 |
| 5 | GECOS: full name, comments | root |
| 6 | Home directory | /root |
| 7 | Login shell | /bin/sh |
Most of these lines are system accounts: daemon, bin, www-data exist so that services can own files and run without root privileges. Their shell is /bin/false, a program that exits immediately, so nobody can log in as them. nobody, UID 65534, is the deliberately powerless account. Real people usually start at UID 1000.
/etc/group: four fields
Each line is name:password:GID:members. The members field is a comma-separated list of users who have this group as a *supplementary* group; users whose primary GID points here are not repeated. In the VM, wheel:x:10:root says root is a member of wheel, the traditional group allowed to become root. Group passwords are an obsolete feature, hence the x nobody uses.
/etc/shadow: the hashes
/etc/passwd must be world-readable, because ls -l needs to turn UIDs into names for everyone. Password hashes used to sit in field 2, where anybody could copy them and crack them offline. The fix was to move them to /etc/shadow, readable only by root, and leave an x behind. A shadow line has nine fields: name, hash, date of last change (days since 1970), minimum and maximum age, warning period, inactivity, expiry and a spare. The hash field tells you the state of the account at a glance: a string starting with $1$, $5$ or $6$ is a real hash (MD5, SHA-256, SHA-512); ! or * means locked, no password will ever match; an empty field means no password is required at all. Look at root in this VM: root::10933:0:99999:7::: — no password, which is why the console drops you straight into a shell.
Reading them with the usual tools
~% grep '^root:' /etc/passwd
root:x:0:0:root:/root:/bin/sh
~% cut -d: -f1 /etc/passwd | head -3
root
daemon
bin
~% awk -F: '$3 >= 1000 {print $1, $6}' /etc/passwd
nobody /home
~% awk -F: '$7 == "/bin/sh"' /etc/passwd
root:x:0:0:root:/root:/bin/sh
Commands in this lesson
| Command | What it does |
|---|---|
cat /etc/passwd | All user accounts, one per line. |
cat /etc/group | All groups and their supplementary members. |
cat /etc/shadow | Password hashes and ageing (root only). |
grep '^alice:' /etc/passwd | One user's record. |
cut -d: -f1 /etc/passwd | Just the user names. |
awk -F: '$3 == 0' /etc/passwd | Every account with UID 0. |
Quiz
What does the `x` in the second field of /etc/passwd mean?
- The account is locked
- The hash is stored in /etc/shadow
- The password is literally "x"
Which field of /etc/passwd holds the login shell?
- The fifth
- The sixth
- The seventh
A shadow line reads `bob:!:20730:0:99999:7:::`. What is bob's situation?
- He can log in without a password
- His password is "!"
- The account is locked: no password will match
Why is /etc/shadow readable only by root while /etc/passwd is world-readable?
- Because everyone needs to map UIDs to names, but nobody needs the hashes
- Because /etc/shadow is a binary file
- It is a historical accident with no reason
In `/etc/group`, who appears in the fourth field?
- Every user whose primary group it is
- Users who have it as a supplementary group
- The group's owner
Practice
Save root's line from `/etc/passwd` (and only that line) into `/root/lab/l42/root.txt`.
Write the list of all user names (first field of `/etc/passwd`, nothing else) to `/root/lab/l42/names.txt`.
Using `awk`, write the name of every account whose UID is 0 to `/root/lab/l42/uid0.txt`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.