TT Lab
Get started
Learn Learning paths Courses

LFCS — Linux Foundation System Administrator

Creating Users and Groups and Applying Policy

Continue in TT Lab

Goal

You actually create users and groups, apply a password policy, and read the values directly from the three account database files to confirm them.

Why it matters

Account management is an area with reliable points on the LFCS, and it is also the hardest work to undo in practice. If you leave out the one extra option in usermod -G, all of the user's supplementary groups are wiped out, and if that user was an administrator, the recovery path itself disappears. So this lab focuses on building the habit of verifying the result with id and getent every time. The same goes for password policy — the expiry fields in /etc/shadow are not dates but days since 1970, so to judge "is this right" by looking at a value with your eyes, you have to know that rule. The orphan home directory you create in the last step is the seed of the incident where, on a real server, when a UID is reused, someone ends up reading someone else's files.

Steps

  1. Create a group lfcsops with GID 4200 and a group lfcsdev with no GID specified.
  2. Create a user lfcsadm with UID 4201, primary group lfcsops, home directory /home/lfcsadm (actually created), and login shell /bin/bash.
  3. Create a user lfcsdev1 with primary group lfcsdev and give it lfcsops as a supplementary group. Then, leaving the primary group of lfcsadm as it is, add lfcsdev to its supplementary groups.
  4. Create a service account lfcssvc with a UID below 1000 (the system account range), a shell that cannot log in, and no home directory.
  5. Set the password policy of lfcsdev1 to a minimum of 7 days in use, a maximum of 90 days in use, 14 days of expiry warning, and an account expiry date of 2027-12-31.
  6. Set a password for lfcsdev1 and then lock that password. The second field of /etc/shadow must start with an exclamation mark, and the hash must remain after it.
  7. In /root/lfcs-users/report.txt, write three lines: uid=<lfcsadm 의 UID>, gid=<lfcsops 의 GID>, and shadow_max=<lfcsdev1 의 최대 사용 일수> (each followed by the value: the UID of lfcsadm, the GID of lfcsops, and the maximum days in use of lfcsdev1).
  8. Create a temporary account lfcstmp that has a home directory, and then delete only the account, keeping the home. /home/lfcstmp must remain, and there must be no account corresponding to its owner UID.

Notes

Create two groups

Create a group lfcsops with GID 4200 and a group lfcsdev with no GID specified.

The group creation command has an option that sets the GID directly. Specify one and let the system pick the other.

A user with UID, home, and shell specified

Create a user lfcsadm with UID 4201, primary group lfcsops, home directory /home/lfcsadm (actually created), and login shell /bin/bash.

useradd takes the UID, primary group, home path, and login shell through separate options. Note that there is a separate option that actually creates the home directory.

Attaching supplementary groups

Create a user lfcsdev1 with primary group lfcsdev and give it lfcsops as a supplementary group. Then, leaving the primary group of lfcsadm as it is, add lfcsdev to its supplementary groups.

To add while keeping the existing supplementary groups, you need the append option. If you leave it out, the list is replaced wholesale. Check the result with id.

A service account that cannot log in

Create a service account lfcssvc with a UID below 1000 (the system account range), a shell that cannot log in, and no home directory.

There is an option that creates it as a system account and a separate option that does not create a home. For the shell, specify a path that refuses login.

Password expiry policy

Set the password policy of lfcsdev1 to a minimum of 7 days in use, a maximum of 90 days in use, 14 days of expiry warning, and an account expiry date of 2027-12-31.

Minimum, maximum, warning, and account expiry are each a different option. If you give the expiry date as a human-readable date, the tool converts it to the internal format.

Lock the password after setting it

Set a password for lfcsdev1 and then lock that password. The second field of /etc/shadow must start with an exclamation mark, and the hash must remain after it.

There is a tool that sets a password without interactive input. Locking does not delete the hash but puts a mark in front of it, so the password has to exist before you lock it for it to mean anything.

Reading values from the account database

In /root/lfcs-users/report.txt, write three lines: uid=<lfcsadm 의 UID>, gid=<lfcsops 의 GID>, and shadow_max=<lfcsdev1 의 최대 사용 일수> (each followed by the value: the UID of lfcsadm, the GID of lfcsops, and the maximum days in use of lfcsdev1).

The three values are each in a different field of a different file. They are separated by colons, so count the field numbers to pull them out.

Delete only the account and keep the home

Create a temporary account lfcstmp that has a home directory, and then delete only the account, keeping the home. /home/lfcstmp must remain, and there must be no account corresponding to its owner UID.

The delete command has an option that deletes the home along with it. This time you must not use it. Check the owner of the remaining directory.