How to manage users and groups on Ubuntu, and how to configure the sudo command.
Users
# List all available userscat /etc/passwd # List user, id, group, etccut -d : -f 1 /etc/passwd # List only user's names
# Creating user interactively (it's a perl script using `useradd` command)adduser risan
# Create system usersudo useradd -r -M -s /usr/sbin/nologin www-data
# -r => Create system account# -M => Do not create home's directory# -s /usr/sbin/nologin => Set the shell to `nologin` so it cannot be logged into
# Check the currently logged userwho# Or a more complete versionw # The first line contains an uptimeDelete a user:
# Remove user but keep his/her home directorydeluser risan
# Remove user and his/her home directorydeluser risan --remove-homeGroups
# List all available groupscat /etc/group # List group's name and idcut -d : -f 1 /etc/group # List only group's names
# List current user groupsgroups
# List other user groupsgroups www-dataAdd a user to a group:
# Add user to a groupusermod -aG awesomegroup risan
# -a => Append to group(s), can ony be used with -G# -G => A list of groups, seprated by comma
# Give a user sudo privileges by adding it to sudo groupusermod -aG sudo risanDelete a group:
# Remove group if there's no member remainingdelgroup awesomegroup --only-if-emptyThe sudoers File
The sudo command is configured through sudoers files. These files can be found within:
# The default sudoers file/etc/sudoers
# Any custom sudoers files can be put here/etc/sudoers.dThe visudo
When editing the default /etc/sudoers file you have to use the visudo command. With visudo the sudoers file will be validated upon saving. This ensures that the file is valid and prevents you from losing access to the sudo command.
sudo visudoNote that on Ubuntu the default visudo editor is Nano. To change this to vim you can run the following command:
sudo EDITOR=vim visudo
# Or if you want to update the default editor globallysudo update-alternatives --config editorReading the sudoers File
Here’s an example of what the sudoers file looks like:
root ALL=(ALL:ALL) ALL%admin ALL=(ALL) ALL%sudo ALL=(ALL:ALL) ALLLet’s break down the configuration for the root user:
root ALL = (ALL : ALL) ALL(1) (2) (3) (4) (5)
(1) This is the user/group name that is being configured. The percentage sign (%) in the front indicate that it's a group.
(2) `ALL` means that the rules are applied to all HOSTS
(3) `ALL` means that the `root` user can act as ANY USERS using the `sudo` command.
(4) `ALL` means that the `root` user can act as ANY GROUPS using the `sudo` command.
(5) `ALL` means that the `root` can run ANY COMMANDS using `sudo`.Sudo without Password
You can configure the sudo command without a password like this:
risan ALL=(ALL:ALL) NOPASSWD:ALLThis is useful for deployment. You can configure your deployer user or group to have access to restart some services without a sudo password:
# Allow `www-data` group to restart nginx without password%www-data ALL=(ALL:ALL) NOPASSWD:/usr/sbin/service nginx restart
# Or you can allow to `www-data` group to execute any `sudo service nginx ...` command without password%www-data ALL=(ALL:ALL) NOPASSWD:/usr/sbin/service nginx *
# You can even combine command with and without password# Restart nginx requires no password, but you'll need to stop it%www-data ALL=(ALL:ALL) NOPASSWD:/usr/sbin/service nginx restart, PASSWD:/usr/sbin/service nginx stopCreating Additional Sudoers File
We may also add additional sudoers files to the /etc/sudoers.d directory.
# The sudoers files are loaded alphabetically, usually with prefixed numbersudo vim /etc/sudoers.d/10-www-data
# Write the sudo config%www-data ALL=(ALL:ALL) NOPASSWD:/usr/sbin/service nginx restart
# Save and make sure that the sudoers file is own by root with read-only permissionsudo chown root:root /etc/sudoers.d/10-www-datasudo chmod 440 /etc/sudoers.d/10-www-dataGiving Sudo Privileges
To give a user sudo privileges we can simply add the user to the sudo group:
sudo usermod -aG sudo risanOther sudo Commands
Also see How To Edit the Sudoers File on Ubuntu and CentOS | DigitalOcean.
# Switch to root usersudo su
# Swith to other usersudo su risan
# Run as other usersudo -u www-data
# Run as other groupsudo -g www-data
# Our credential will be cached for some time so we don't have to enter a password everytime we run `sudo` command. For security purpose we can force reset the cache with the following command:sudo -k
# To print our privilegessudo -l
# Sometime we forgot to prefix a command with `sudo`, we can repeat the command with sudo like this:sudo !!