Read

Module 5 · Users, groups and permissions

Switching users with su and setting passwords

Become another user for one command or a whole session with su, and manage passwords with passwd: set, lock, unlock.

What you will learn

  • Run a command or open a shell as another user with `su`.
  • Tell `su user` from `su - user` and know when the difference matters.
  • Set, lock and unlock passwords with `passwd` and read the result in `/etc/shadow`.

su: substitute user

su starts a new shell as another user. With no argument it means root; with a name it means that user. Normally you must type the target's password, but root may become anyone without one, which is why, as root in the lab, su bob just works. When you are done, exit returns you to the shell you came from: su does not *change* your session, it nests a new one inside it.

The lone dash matters. su bob keeps your current directory and most of your environment; you are bob, but standing in root's folder with root's variables. su - bob (or su -l bob) is a login shell: it clears the environment, moves to bob's home and reads his profile, exactly as if bob had logged in. For testing "what does bob see" the dash form is the honest one. For a one-off command, -c runs it and comes straight back: su bob -c 'id'.

~% su bob -c whoami
bob
~% su bob -c 'touch /tmp/from-bob.txt; ls -l /tmp/from-bob.txt'
-rw-r--r--    1 bob      bob              0 Oct  4 18:53 /tmp/from-bob.txt
~% su bob -c 'cat /root/notes.txt'
cat: can't open '/root/notes.txt': Permission denied
~% su bob
/root $ whoami
bob
/root $ exit
~%

That Permission denied is the whole point of users: /root is drwx------, so bob cannot even look inside. The file bob created in /tmp belongs to bob, not to the root shell that launched su. This is how you test permissions without a second keyboard.

passwd: set, lock, unlock

passwd changes your own password; passwd bob changes bob's, something only root may do. It asks twice and writes a salted hash into /etc/shadow. Three flags manage the account state without knowing the password: -l locks it by putting ! in front of the hash, -u unlocks it by removing the !, and -d deletes it, leaving the field empty so no password is needed. BusyBox refuses very short passwords with Bad password: too short, which is a feature.

~% passwd bob
Changing password for bob
New password: 
Retype password: 
passwd: password for bob changed by root
~% grep '^bob:' /etc/shadow | cut -c1-24
bob:$1$yQpzV8RS$NpjS7F2
~% passwd -l bob
passwd: password for bob changed by root
~% grep '^bob:' /etc/shadow | cut -d: -f2 | cut -c1-3
!$1
CommandHash field afterwardsCan bob log in with a password?
adduser -D bob!No (locked, none set)
passwd bob$1$salt$hashYes, with that password
passwd -l bob!$1$salt$hashNo, but the hash is kept
passwd -u bob$1$salt$hashYes again
passwd -d bob(empty)Yes, with no password at all

Commands in this lesson

CommandWhat it does
su bobShell as bob, keeping your cwd and environment.
su - bobLogin shell as bob: his home, his environment.
su bob -c 'id'Run one command as bob and return.
exitLeave the su shell and return to the previous user.
passwd bobSet bob's password (root only for other users).
passwd -l bobLock the account (prefix the hash with !).
passwd -u bobUnlock it again.
passwd -d bobRemove the password entirely.

Quiz

  1. What is the difference between `su bob` and `su - bob`?

    • None; the dash is optional
    • The dash gives a login shell: bob's home, environment and profile
    • The dash makes su ask for a password
  2. Why does `su bob` not ask for a password in the lab?

    • Because bob has no password
    • Because root can become any user without authenticating
    • Because su is broken in BusyBox
  3. What does `passwd -l bob` write to /etc/shadow?

    • It empties the hash field
    • It deletes bob's line
    • It prefixes the hash with `!`
  4. How do you run exactly one command as bob and come back to root?

    • `su bob -c 'command'`
    • `su bob command`
    • `run-as bob command`

Practice

  1. The user `bob` exists. Acting as bob, create the file `/tmp/from-bob.txt` so that bob is its owner.

  2. Give `bob` a password (any one you like, at least 6 characters).

  3. `bob` currently has an empty password. Lock his account.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.