Module 5 · Users, groups and permissions
Switching users with su and setting passwords
Become another user for one command or a whole session with su, and manage passwords with passwd: set, lock, unlock.
What you will learn
- Run a command or open a shell as another user with `su`.
- Tell `su user` from `su - user` and know when the difference matters.
- Set, lock and unlock passwords with `passwd` and read the result in `/etc/shadow`.
su: substitute user
su starts a new shell as another user. With no argument it means root; with a name it means that user. Normally you must type the target's password, but root may become anyone without one, which is why, as root in the lab, su bob just works. When you are done, exit returns you to the shell you came from: su does not *change* your session, it nests a new one inside it.
The lone dash matters. su bob keeps your current directory and most of your environment; you are bob, but standing in root's folder with root's variables. su - bob (or su -l bob) is a login shell: it clears the environment, moves to bob's home and reads his profile, exactly as if bob had logged in. For testing "what does bob see" the dash form is the honest one. For a one-off command, -c runs it and comes straight back: su bob -c 'id'.
~% su bob -c whoami
bob
~% su bob -c 'touch /tmp/from-bob.txt; ls -l /tmp/from-bob.txt'
-rw-r--r-- 1 bob bob 0 Oct 4 18:53 /tmp/from-bob.txt
~% su bob -c 'cat /root/notes.txt'
cat: can't open '/root/notes.txt': Permission denied
~% su bob
/root $ whoami
bob
/root $ exit
~%
That Permission denied is the whole point of users: /root is drwx------, so bob cannot even look inside. The file bob created in /tmp belongs to bob, not to the root shell that launched su. This is how you test permissions without a second keyboard.
passwd: set, lock, unlock
passwd changes your own password; passwd bob changes bob's, something only root may do. It asks twice and writes a salted hash into /etc/shadow. Three flags manage the account state without knowing the password: -l locks it by putting ! in front of the hash, -u unlocks it by removing the !, and -d deletes it, leaving the field empty so no password is needed. BusyBox refuses very short passwords with Bad password: too short, which is a feature.
~% passwd bob
Changing password for bob
New password:
Retype password:
passwd: password for bob changed by root
~% grep '^bob:' /etc/shadow | cut -c1-24
bob:$1$yQpzV8RS$NpjS7F2
~% passwd -l bob
passwd: password for bob changed by root
~% grep '^bob:' /etc/shadow | cut -d: -f2 | cut -c1-3
!$1
| Command | Hash field afterwards | Can bob log in with a password? |
|---|---|---|
adduser -D bob | ! | No (locked, none set) |
passwd bob | $1$salt$hash | Yes, with that password |
passwd -l bob | !$1$salt$hash | No, but the hash is kept |
passwd -u bob | $1$salt$hash | Yes again |
passwd -d bob | (empty) | Yes, with no password at all |
Commands in this lesson
| Command | What it does |
|---|---|
su bob | Shell as bob, keeping your cwd and environment. |
su - bob | Login shell as bob: his home, his environment. |
su bob -c 'id' | Run one command as bob and return. |
exit | Leave the su shell and return to the previous user. |
passwd bob | Set bob's password (root only for other users). |
passwd -l bob | Lock the account (prefix the hash with !). |
passwd -u bob | Unlock it again. |
passwd -d bob | Remove the password entirely. |
Quiz
What is the difference between `su bob` and `su - bob`?
- None; the dash is optional
- The dash gives a login shell: bob's home, environment and profile
- The dash makes su ask for a password
Why does `su bob` not ask for a password in the lab?
- Because bob has no password
- Because root can become any user without authenticating
- Because su is broken in BusyBox
What does `passwd -l bob` write to /etc/shadow?
- It empties the hash field
- It deletes bob's line
- It prefixes the hash with `!`
How do you run exactly one command as bob and come back to root?
- `su bob -c 'command'`
- `su bob command`
- `run-as bob command`
Practice
The user `bob` exists. Acting as bob, create the file `/tmp/from-bob.txt` so that bob is its owner.
Give `bob` a password (any one you like, at least 6 characters).
`bob` currently has an empty password. Lock his account.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.