Users, groups, and where their data lives
/etc/passwd, /etc/shadow, /etc/group, and the commands that manage them. · 9 min
Every user account has a numeric User ID (UID) — the kernel and filesystem only ever deal in UIDs, not usernames; the username is a convenience layer resolved via `/etc/passwd`. UID 0 is always root, the superuser with unrestricted access. Regular user UIDs conventionally start at 1000 on most modern distributions, with UIDs below that reserved for system accounts and services that need their own identity but aren't meant for interactive login.
`/etc/passwd` lists every user account: username, UID, primary GID, a description field, home directory, and login shell — despite the name, it hasn't stored actual passwords in decades; that field is now always an `x`, a placeholder pointing to `/etc/shadow`. `/etc/shadow` holds the actual (hashed, never plaintext) passwords and password-aging policy, and is readable only by root — this separation exists specifically so that `/etc/passwd`, which many tools need to read to resolve usernames, doesn't need to expose password hashes to do so.
`/etc/group` lists every group, its GID, and its member usernames. Every user has exactly one primary group (assigned at creation, usually matching their username by default) but can belong to any number of supplementary groups, which is how you grant access to shared resources (a "developers" group with write access to a shared directory) without changing anyone's primary identity.
| Command | Purpose | Example |
|---|---|---|
| useradd | Create a new user account | sudo useradd -m -s /bin/bash alice |
| usermod | Modify an existing user account | sudo usermod -aG developers alice |
| userdel | Delete a user account | sudo userdel -r alice # -r also removes their home directory |
| passwd | Set or change a user's password | — |
| groupadd | Create a new group | sudo groupadd developers |
| id | Show a user's UID, primary GID, and all supplementary group memberships | id alice |
| groups | List the groups a user belongs to | — |
Common Mistakes
- ⚠ Using `usermod -G` (capital G, no `-a`) to add a supplementary group — this replaces ALL existing supplementary groups instead of adding one, silently removing the user from every other group they were in
- ⚠ Forgetting `-m` when creating a user with `useradd`, resulting in no home directory being created
- ⚠ Assuming deleting a user (`userdel`) also removes files they own elsewhere on the system — it doesn't, by default, outside their home directory
Hands-On Lab
Create users and a shared group
Objectives
- ✓ Create two new user accounts with home directories
- ✓ Create a shared group and add both users to it
- ✓ Verify group membership without guessing
Instructions
- Create user `alice` with `sudo useradd -m -s /bin/bash alice`, then set her password with `sudo passwd alice`.
- Repeat for a user `bob`.
- Create a group called `project-team` with `sudo groupadd project-team`.
- Add both `alice` and `bob` to `project-team` as a supplementary group using `usermod -aG` (note the `-a` — append, don't replace).
- Confirm both memberships with `id alice` and `id bob`, checking that `project-team` appears in each output.
Hints (1)
- If a user doesn't see their new group membership immediately, they may need to log out and back in — group membership is evaluated at login time, not live.
Takeaway: `/etc/passwd` is world-readable identity data; `/etc/shadow` is root-only secret data — that split is exactly why so many tools can resolve "UID 1001 = alice" without ever touching a password hash.