IT271 Networking and System Administration

Networking and System AdministrationUnit 310 min read

User & Group Management: Roles, Permissions, Commands & Security

Unit 3 of Networking and System Administration covers user/group management in Linux/Windows systems, including creation, permissions, role-based access control (RBAC), and security best practices with practical examples from real-world IT environments.

Core Concepts: Users and Groups

What are Users and Groups?

  • User: An account that allows a person or process to access system resources. Each user has a unique username, password, and associated permissions.
  • Group: A collection of users who share common access rights to system resources. Groups simplify permission management.
classDiagram
    class User {
        +username: string
        +UID: integer
        +home_directory: string
        +shell: string
    }
    class Group {
        +groupname: string
        +GID: integer
        +members: User[]
    }
    User "1" --> "0..*" Group : belongs_to
    Group "1" --> "1..*" User : contains

Why Use Groups?

  • Centralized Control: Assign permissions to a group instead of individual users.
  • Efficiency: Manage permissions for multiple users at once.
  • Security: Limit access to sensitive resources by grouping users with similar needs.

Key Files for User/Group Management

File Purpose
/etc/passwd Stores user account information (username, UID, home directory, shell).
/etc/shadow Stores encrypted passwords and account aging information.
/etc/group Stores group information (groupname, GID, members).

User Management Commands

Creating and Managing Users

# Create a new user
sudo useradd -m -s /bin/bash username

# Set password
sudo passwd username

# Delete a user
sudo userdel -r username

Modifying User Attributes

# Change username
sudo usermod -l newname oldname

# Change home directory
sudo usermod -d /new/home username

# Change shell
sudo usermod -s /bin/zsh username

Checking User Information

# Display user details
id username

# List all users
cut -d: -f1 /etc/passwd

# Check login history
last username

Group Management Commands

Creating and Managing Groups

# Create a new group
sudo groupadd developers

# Add a user to a group
sudo usermod -aG developers username

# Delete a group
sudo groupdel developers

Checking Group Information

# Display group details
getent group developers

# List all groups
cut -d: -f1 /etc/group

File Permissions and Ownership

Understanding Permissions

Permissions are divided into three categories:

  • User (Owner): u
  • Group: g
  • Others: o

Permissions can be:

  • Read (r): 4
  • Write (w): 2
  • Execute (x): 1

Example: rwxr-xr-- = 754 (4+2+1 for user, 4+1 for group, 4 for others).

stateDiagram-v2
    [*] --> PermissionCheck: Check file permissions
    PermissionCheck --> User: User (Owner)?
    User --> HasPermission: Yes
    HasPermission --> AccessGranted: Grant access
    User --> NoPermission: No
    NoPermission --> Group: Check group?
    Group --> HasPermission: Yes
    HasPermission --> AccessGranted
    Group --> NoPermission: No
    NoPermission --> Others: Check others?
    Others --> HasPermission: Yes
    HasPermission --> AccessGranted
    Others --> NoPermission: No
    NoPermission --> AccessDenied: Deny access
    AccessGranted --> [*]
    AccessDenied --> [*]

Changing Permissions

# Change permissions using symbolic notation
chmod u=rwx,g=rx,o=r file.txt

# Change permissions using numeric notation
chmod 754 file.txt

# Change ownership
sudo chown newowner:newgroup file.txt

Special Permissions and Defaults

SetUID, SetGID, and Sticky Bit

Permission Symbolic Numeric Purpose
SetUID s 4 Run executable with owner's permissions.
SetGID s 2 Run executable with group's permissions.
Sticky Bit t 1 Only owner can delete files in a directory (e.g., /tmp).

Example:

chmod u+s script.sh  # SetUID
chmod g+s folder     # SetGID
chmod o+t /tmp       # Sticky Bit

Role-Based Access Control (RBAC)

What is RBAC?

RBAC is a security model that restricts system access based on user roles (e.g., admin, editor, viewer). It simplifies permission management by assigning roles instead of individual permissions.

Example: RBAC in a Company

Role Permissions
Admin Full access to all files, users, and settings.
Editor Can create, edit, and delete files in their assigned directories.
Viewer Can only read files and view system status.
mindmap
  root((RBAC in Company))
    Admin
      Full Access
      User Management
      System Configuration
    Editor
      File Creation
      File Editing
      File Deletion
    Viewer
      File Reading
      System Monitoring

In the Real World

1. eSewa (Nepal)

  • Idea Used: Group-based access control
  • How: eSewa uses groups to manage permissions for different roles (e.g., admins, agents, customers). Admins have full access to user data and transactions, while agents can only process payments for their assigned regions.
  • Example: When a new agent joins, they are added to the agents group, granting them access only to their designated services (e.g., electricity bill payments for Kathmandu).

2. Khalti (Nepal)

  • Idea Used: User permissions and SetUID
  • How: Khalti uses SetUID on critical executables (e.g., transaction processors) to ensure they run with the permissions of the khalti system user, not the user invoking them. This prevents unauthorized access to financial data.
  • Example: When you transfer money via Khalti, the backend script runs with elevated privileges (SetUID) to securely process the transaction in the database.

3. Ncell (Nepal)

  • Idea Used: Role-Based Access Control (RBAC)
  • How: Ncell’s internal systems use RBAC to manage employee access. For example:
    • technicians can only access customer service logs for their assigned areas.
    • managers can view all logs and approve technician requests.
    • admins can modify system configurations and user roles.
  • Example: A technician in Pokhara cannot access customer data from Kathmandu unless promoted to a supervisor role.

Worked Example: Managing Users for a Small Business

Scenario

You are the system administrator for a small IT firm with 10 employees. You need to:

  1. Create users for the team.
  2. Assign them to appropriate groups based on their roles.
  3. Set permissions for shared project folders.

Step-by-Step Solution

1. Create Users

sudo useradd -m -s /bin/bash developer1
sudo passwd developer1
sudo useradd -m -s /bin/bash designer1
sudo passwd designer1

2. Create Groups

sudo groupadd developers
sudo groupadd designers

3. Add Users to Groups

sudo usermod -aG developers developer1
sudo usermod -aG designers designer1

4. Create a Shared Project Folder

sudo mkdir /projects/website
sudo chown :developers /projects/website  # Set group ownership
sudo chmod 775 /projects/website         # Give group full access

5. Verify Permissions

ls -ld /projects/website
# Output: drwxrwxr-x 2 root developers 4096 Jun 10 10:00 /projects/website

6. Test Access

  • developer1 can now read, write, and execute files in /projects/website.
  • designer1 cannot access the folder unless added to the developers group.

Comparing User Management in Linux and Windows

Feature Linux Windows
User Database /etc/passwd, /etc/shadow Active Directory or SAM database
Group Management /etc/group Local Groups or AD Groups
Permission Model rwx (read, write, execute) NTFS permissions (Full Control, Modify, Read)
Command to Add User useradd/adduser net user or PowerShell New-LocalUser
Command to Add Group groupadd net localgroup or PowerShell New-LocalGroup
Default Shell /bin/bash, /bin/zsh cmd.exe or PowerShell

Common Mistakes and How to Avoid Them

1. Over-Permissive Directories

  • Mistake: Setting 777 (full access for everyone) on sensitive folders.
  • Fix: Use 755 for directories and 644 for files, restricting access to owners and groups.

2. Ignoring Group Permissions

  • Mistake: Relying only on user permissions and forgetting group assignments.
  • Fix: Always assign users to relevant groups and set group permissions (g+rwx).

3. Not Using SetUID/SetGID Securely

  • Mistake: Applying SetUID to all executables without need.
  • Fix: Only use SetUID on trusted binaries (e.g., passwd, sudo).

4. Hardcoding Passwords

  • Mistake: Storing passwords in plaintext or scripts.
  • Fix: Use encrypted passwords (/etc/shadow) and tools like sudo for privileged tasks.

Exam Tip

For the TU exam on this unit, expect:

  1. Short Answer Questions (10 marks):
    • Define user, group, UID, GID, SetUID, SetGID, and Sticky Bit.
    • List commands to create users/groups, change permissions, and check ownership.
  2. Practical Questions (20 marks):
    • Write commands to:
      • Create a user and add them to a group.
      • Set permissions for a file/directory (symbolic and numeric).
      • Change ownership of a file.
    • Interpret permission outputs (e.g., ls -l, id username).
  3. Scenario-Based Questions (30 marks):
    • Design a user/group structure for a given scenario (e.g., a school, hospital, or company).
    • Explain how RBAC would be implemented in a real-world system (e.g., eSewa, Khalti).
    • Troubleshoot permission issues (e.g., "Why can’t User A access File X?").
  4. Diagrams (10 marks):
    • Draw a classDiagram or stateDiagram explaining user/group relationships or permission checks.
    • Label a /etc/passwd or /etc/group entry with its fields.

Key Focus Areas:

  • Memorize commands (useradd, usermod, groupadd, chmod, chown).
  • Understand permission calculations (e.g., 754 = rwxr-xr--).
  • Practice designing user/group structures for different roles.
  • Relate concepts to real-world examples (e.g., eSewa, Khalti, Ncell).

Based on the TU BIM syllabus for Networking and System Administration (IT271), unit 3.

Discussion

Loading…