Networking and System AdministrationUnit 310 min read
User & Group Management: Roles, Permissions, Commands & Security
Unit 3 of Networking and System Administration covers user/group management in Linux/Windows systems, including creation, permissions, role-based access control (RBAC), and security best practices with practical examples from real-world IT environments.
Core Concepts: Users and Groups
What are Users and Groups?
- User: An account that allows a person or process to access system resources. Each user has a unique username, password, and associated permissions.
- Group: A collection of users who share common access rights to system resources. Groups simplify permission management.
classDiagram
class User {
+username: string
+UID: integer
+home_directory: string
+shell: string
}
class Group {
+groupname: string
+GID: integer
+members: User[]
}
User "1" --> "0..*" Group : belongs_to
Group "1" --> "1..*" User : containsWhy Use Groups?
- Centralized Control: Assign permissions to a group instead of individual users.
- Efficiency: Manage permissions for multiple users at once.
- Security: Limit access to sensitive resources by grouping users with similar needs.
Key Files for User/Group Management
| File | Purpose |
|---|---|
/etc/passwd |
Stores user account information (username, UID, home directory, shell). |
/etc/shadow |
Stores encrypted passwords and account aging information. |
/etc/group |
Stores group information (groupname, GID, members). |
User Management Commands
Creating and Managing Users
# Create a new user
sudo useradd -m -s /bin/bash username
# Set password
sudo passwd username
# Delete a user
sudo userdel -r username
Modifying User Attributes
# Change username
sudo usermod -l newname oldname
# Change home directory
sudo usermod -d /new/home username
# Change shell
sudo usermod -s /bin/zsh username
Checking User Information
# Display user details
id username
# List all users
cut -d: -f1 /etc/passwd
# Check login history
last username
Group Management Commands
Creating and Managing Groups
# Create a new group
sudo groupadd developers
# Add a user to a group
sudo usermod -aG developers username
# Delete a group
sudo groupdel developers
Checking Group Information
# Display group details
getent group developers
# List all groups
cut -d: -f1 /etc/group
File Permissions and Ownership
Understanding Permissions
Permissions are divided into three categories:
- User (Owner):
u - Group:
g - Others:
o
Permissions can be:
- Read (r): 4
- Write (w): 2
- Execute (x): 1
Example: rwxr-xr-- = 754 (4+2+1 for user, 4+1 for group, 4 for others).
stateDiagram-v2
[*] --> PermissionCheck: Check file permissions
PermissionCheck --> User: User (Owner)?
User --> HasPermission: Yes
HasPermission --> AccessGranted: Grant access
User --> NoPermission: No
NoPermission --> Group: Check group?
Group --> HasPermission: Yes
HasPermission --> AccessGranted
Group --> NoPermission: No
NoPermission --> Others: Check others?
Others --> HasPermission: Yes
HasPermission --> AccessGranted
Others --> NoPermission: No
NoPermission --> AccessDenied: Deny access
AccessGranted --> [*]
AccessDenied --> [*]Changing Permissions
# Change permissions using symbolic notation
chmod u=rwx,g=rx,o=r file.txt
# Change permissions using numeric notation
chmod 754 file.txt
# Change ownership
sudo chown newowner:newgroup file.txt
Special Permissions and Defaults
SetUID, SetGID, and Sticky Bit
| Permission | Symbolic | Numeric | Purpose |
|---|---|---|---|
| SetUID | s |
4 | Run executable with owner's permissions. |
| SetGID | s |
2 | Run executable with group's permissions. |
| Sticky Bit | t |
1 | Only owner can delete files in a directory (e.g., /tmp). |
Example:
chmod u+s script.sh # SetUID
chmod g+s folder # SetGID
chmod o+t /tmp # Sticky Bit
Role-Based Access Control (RBAC)
What is RBAC?
RBAC is a security model that restricts system access based on user roles (e.g., admin, editor, viewer). It simplifies permission management by assigning roles instead of individual permissions.
Example: RBAC in a Company
| Role | Permissions |
|---|---|
| Admin | Full access to all files, users, and settings. |
| Editor | Can create, edit, and delete files in their assigned directories. |
| Viewer | Can only read files and view system status. |
mindmap
root((RBAC in Company))
Admin
Full Access
User Management
System Configuration
Editor
File Creation
File Editing
File Deletion
Viewer
File Reading
System MonitoringIn the Real World
1. eSewa (Nepal)
- Idea Used: Group-based access control
- How: eSewa uses groups to manage permissions for different roles (e.g.,
admins,agents,customers). Admins have full access to user data and transactions, while agents can only process payments for their assigned regions. - Example: When a new agent joins, they are added to the
agentsgroup, granting them access only to their designated services (e.g., electricity bill payments for Kathmandu).
2. Khalti (Nepal)
- Idea Used: User permissions and SetUID
- How: Khalti uses SetUID on critical executables (e.g., transaction processors) to ensure they run with the permissions of the
khaltisystem user, not the user invoking them. This prevents unauthorized access to financial data. - Example: When you transfer money via Khalti, the backend script runs with elevated privileges (SetUID) to securely process the transaction in the database.
3. Ncell (Nepal)
- Idea Used: Role-Based Access Control (RBAC)
- How: Ncell’s internal systems use RBAC to manage employee access. For example:
technicianscan only access customer service logs for their assigned areas.managerscan view all logs and approve technician requests.adminscan modify system configurations and user roles.
- Example: A technician in Pokhara cannot access customer data from Kathmandu unless promoted to a
supervisorrole.
Worked Example: Managing Users for a Small Business
Scenario
You are the system administrator for a small IT firm with 10 employees. You need to:
- Create users for the team.
- Assign them to appropriate groups based on their roles.
- Set permissions for shared project folders.
Step-by-Step Solution
1. Create Users
sudo useradd -m -s /bin/bash developer1
sudo passwd developer1
sudo useradd -m -s /bin/bash designer1
sudo passwd designer1
2. Create Groups
sudo groupadd developers
sudo groupadd designers
3. Add Users to Groups
sudo usermod -aG developers developer1
sudo usermod -aG designers designer1
4. Create a Shared Project Folder
sudo mkdir /projects/website
sudo chown :developers /projects/website # Set group ownership
sudo chmod 775 /projects/website # Give group full access
5. Verify Permissions
ls -ld /projects/website
# Output: drwxrwxr-x 2 root developers 4096 Jun 10 10:00 /projects/website
6. Test Access
developer1can now read, write, and execute files in/projects/website.designer1cannot access the folder unless added to thedevelopersgroup.
Comparing User Management in Linux and Windows
| Feature | Linux | Windows |
|---|---|---|
| User Database | /etc/passwd, /etc/shadow |
Active Directory or SAM database |
| Group Management | /etc/group |
Local Groups or AD Groups |
| Permission Model | rwx (read, write, execute) | NTFS permissions (Full Control, Modify, Read) |
| Command to Add User | useradd/adduser |
net user or PowerShell New-LocalUser |
| Command to Add Group | groupadd |
net localgroup or PowerShell New-LocalGroup |
| Default Shell | /bin/bash, /bin/zsh |
cmd.exe or PowerShell |
Common Mistakes and How to Avoid Them
1. Over-Permissive Directories
- Mistake: Setting
777(full access for everyone) on sensitive folders. - Fix: Use
755for directories and644for files, restricting access to owners and groups.
2. Ignoring Group Permissions
- Mistake: Relying only on user permissions and forgetting group assignments.
- Fix: Always assign users to relevant groups and set group permissions (
g+rwx).
3. Not Using SetUID/SetGID Securely
- Mistake: Applying SetUID to all executables without need.
- Fix: Only use SetUID on trusted binaries (e.g.,
passwd,sudo).
4. Hardcoding Passwords
- Mistake: Storing passwords in plaintext or scripts.
- Fix: Use encrypted passwords (
/etc/shadow) and tools likesudofor privileged tasks.
Exam Tip
For the TU exam on this unit, expect:
- Short Answer Questions (10 marks):
- Define
user,group,UID,GID,SetUID,SetGID, andSticky Bit. - List commands to create users/groups, change permissions, and check ownership.
- Define
- Practical Questions (20 marks):
- Write commands to:
- Create a user and add them to a group.
- Set permissions for a file/directory (symbolic and numeric).
- Change ownership of a file.
- Interpret permission outputs (e.g.,
ls -l,id username).
- Write commands to:
- Scenario-Based Questions (30 marks):
- Design a user/group structure for a given scenario (e.g., a school, hospital, or company).
- Explain how RBAC would be implemented in a real-world system (e.g., eSewa, Khalti).
- Troubleshoot permission issues (e.g., "Why can’t User A access File X?").
- Diagrams (10 marks):
- Draw a
classDiagramorstateDiagramexplaining user/group relationships or permission checks. - Label a
/etc/passwdor/etc/groupentry with its fields.
- Draw a
Key Focus Areas:
- Memorize commands (
useradd,usermod,groupadd,chmod,chown). - Understand permission calculations (e.g.,
754=rwxr-xr--). - Practice designing user/group structures for different roles.
- Relate concepts to real-world examples (e.g., eSewa, Khalti, Ncell).
Based on the TU BIM syllabus for Networking and System Administration (IT271), unit 3.
Discussion
Loading…