LFCS — Linux Foundation System Administrator
Creating Users and Groups and Applying Policy
Goal
You actually create users and groups, apply a password policy, and read the values directly from the three account database files to confirm them.
Why it matters
Account management is an area with reliable points on the LFCS, and it is also the hardest work to undo in practice. If you leave out the one extra option in usermod -G, all of the user's supplementary groups are wiped out, and if that user was an administrator, the recovery path itself disappears. So this lab focuses on building the habit of verifying the result with id and getent every time. The same goes for password policy — the expiry fields in /etc/shadow are not dates but days since 1970, so to judge "is this right" by looking at a value with your eyes, you have to know that rule. The orphan home directory you create in the last step is the seed of the incident where, on a real server, when a UID is reused, someone ends up reading someone else's files.
Steps
- Create a group
lfcsopswith GID 4200 and a grouplfcsdevwith no GID specified. - Create a user
lfcsadmwith UID 4201, primary grouplfcsops, home directory/home/lfcsadm(actually created), and login shell/bin/bash. - Create a user
lfcsdev1with primary grouplfcsdevand give itlfcsopsas a supplementary group. Then, leaving the primary group oflfcsadmas it is, addlfcsdevto its supplementary groups. - Create a service account
lfcssvcwith a UID below 1000 (the system account range), a shell that cannot log in, and no home directory. - Set the password policy of
lfcsdev1to a minimum of 7 days in use, a maximum of 90 days in use, 14 days of expiry warning, and an account expiry date of2027-12-31. - Set a password for
lfcsdev1and then lock that password. The second field of/etc/shadowmust start with an exclamation mark, and the hash must remain after it. - In
/root/lfcs-users/report.txt, write three lines:uid=<lfcsadm 의 UID>,gid=<lfcsops 의 GID>, andshadow_max=<lfcsdev1 의 최대 사용 일수>(each followed by the value: the UID of lfcsadm, the GID of lfcsops, and the maximum days in use of lfcsdev1). - Create a temporary account
lfcstmpthat has a home directory, and then delete only the account, keeping the home./home/lfcstmpmust remain, and there must be no account corresponding to its owner UID.
Notes
- Depending on the distribution,
useradddoes not create the home directory automatically. Even if a path shows ingetent passwd, the directory may not exist. - You can set a password with
chpasswdwithout interactive input. - Fields 3 and 8 of
/etc/shadoware days since 1970-01-01, not dates. - A common mistake: if you leave out the append option when adding a supplementary group, all the existing supplementary groups are replaced.
Create two groups
Create a group lfcsops with GID 4200 and a group lfcsdev with no GID specified.
The group creation command has an option that sets the GID directly. Specify one and let the system pick the other.
A user with UID, home, and shell specified
Create a user lfcsadm with UID 4201, primary group lfcsops, home directory /home/lfcsadm (actually created), and login shell /bin/bash.
useradd takes the UID, primary group, home path, and login shell through separate options. Note that there is a separate option that actually creates the home directory.
Attaching supplementary groups
Create a user lfcsdev1 with primary group lfcsdev and give it lfcsops as a supplementary group. Then, leaving the primary group of lfcsadm as it is, add lfcsdev to its supplementary groups.
To add while keeping the existing supplementary groups, you need the append option. If you leave it out, the list is replaced wholesale. Check the result with id.
A service account that cannot log in
Create a service account lfcssvc with a UID below 1000 (the system account range), a shell that cannot log in, and no home directory.
There is an option that creates it as a system account and a separate option that does not create a home. For the shell, specify a path that refuses login.
Password expiry policy
Set the password policy of lfcsdev1 to a minimum of 7 days in use, a maximum of 90 days in use, 14 days of expiry warning, and an account expiry date of 2027-12-31.
Minimum, maximum, warning, and account expiry are each a different option. If you give the expiry date as a human-readable date, the tool converts it to the internal format.
Lock the password after setting it
Set a password for lfcsdev1 and then lock that password. The second field of /etc/shadow must start with an exclamation mark, and the hash must remain after it.
There is a tool that sets a password without interactive input. Locking does not delete the hash but puts a mark in front of it, so the password has to exist before you lock it for it to mean anything.
Reading values from the account database
In /root/lfcs-users/report.txt, write three lines: uid=<lfcsadm 의 UID>, gid=<lfcsops 의 GID>, and shadow_max=<lfcsdev1 의 최대 사용 일수> (each followed by the value: the UID of lfcsadm, the GID of lfcsops, and the maximum days in use of lfcsdev1).
The three values are each in a different field of a different file. They are separated by colons, so count the field numbers to pull them out.
Delete only the account and keep the home
Create a temporary account lfcstmp that has a home directory, and then delete only the account, keeping the home. /home/lfcstmp must remain, and there must be no account corresponding to its owner UID.
The delete command has an option that deletes the home along with it. This time you must not use it. Check the owner of the remaining directory.