User and Group Management
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
Linux is a multi-user operating system. Properly managing users and groups is the foundation of system security. This article explains how to create, modify, and delete users and groups on EL systems, as well as the structure of the related configuration files.
What You Will Learn
Section titled “What You Will Learn”- Create, modify, and delete users
- Manage user groups
- Understand the structure of
/etc/passwd,/etc/shadow, and/etc/group - Use the
idcommand to view user information - Configure password expiration policies
Prerequisites
Section titled “Prerequisites”- A system with EL 9.x installed
- A user account with
sudoprivileges
User Management
Section titled “User Management”View Current User Information
Section titled “View Current User Information”$ iduid=1000(admin) gid=1000(admin) groups=1000(admin),10(wheel)$ id username$ whoamiadminCreating Users
Section titled “Creating Users”$ sudo useradd webuserThis automatically performs the following actions:
- Adds a user record to
/etc/passwd - Adds a password record to
/etc/shadow - Creates a group with the same name
- Creates the home directory
/home/webuser - Copies default configuration files from
/etc/skelto the home directory
$ sudo passwd webuserChanging password for user webuser.New password:Retype new password:passwd: all authentication tokens updated successfully.Common useradd Options
Section titled “Common useradd Options”$ sudo useradd -d /opt/appuser appuser$ sudo useradd -s /bin/zsh devuser$ sudo useradd -u 1500 customuser$ sudo useradd -G wheel,docker deploy$ sudo useradd -r -s /sbin/nologin appserviceOptions summary:
| Option | Description |
|---|---|
-d <directory> | Specify the home directory |
-s <shell> | Specify the login shell |
-u <UID> | Specify the UID |
-g <primary group> | Specify the primary group |
-G <supplementary groups> | Specify supplementary groups (comma-separated) |
-m | Force creation of the home directory (default behavior) |
-M | Do not create a home directory |
-r | Create a system user |
-e <date> | Set the account expiration date (YYYY-MM-DD) |
-c <comment> | Set the user comment (full name, etc.) |
Modifying Users
Section titled “Modifying Users”$ sudo usermod -s /bin/zsh webuser$ sudo usermod -aG wheel webuser$ sudo usermod -l newname oldname$ sudo usermod -L webuser$ sudo usermod -U webuser$ sudo usermod -e 2026-12-31 tempuserDeleting Users
Section titled “Deleting Users”$ sudo userdel webuser$ sudo userdel -r webuserGroup Management
Section titled “Group Management”Viewing Group Information
Section titled “Viewing Group Information”$ groupsadmin wheel$ groups webuser$ getent group wheelwheel:x:10:admin,deployCreating Groups
Section titled “Creating Groups”$ sudo groupadd developers$ sudo groupadd -g 2000 dbadminAdding Users to Groups
Section titled “Adding Users to Groups”$ sudo usermod -aG developers webuser$ sudo gpasswd -a webuser developers$ sudo gpasswd -d webuser developersModifying and Deleting Groups
Section titled “Modifying and Deleting Groups”$ sudo groupmod -n newname oldname$ sudo groupdel developersKey Configuration Files
Section titled “Key Configuration Files”/etc/passwd
Section titled “/etc/passwd”Stores basic user account information, one user per line, with 7 fields:
username:password-placeholder:UID:GID:comment:home-directory:shell$ grep webuser /etc/passwdwebuser:x:1001:1001::/home/webuser:/bin/bashField descriptions:
| Field | Example | Description |
|---|---|---|
| 1 | webuser | Username |
| 2 | x | Password placeholder (actual password stored in /etc/shadow) |
| 3 | 1001 | UID (User ID) |
| 4 | 1001 | GID (Primary Group ID) |
| 5 | (empty) | GECOS comment field (typically the full name) |
| 6 | /home/webuser | Home directory path |
| 7 | /bin/bash | Login shell |
/etc/shadow
Section titled “/etc/shadow”Stores encrypted passwords and password policy information. Only root can read this file.
$ sudo grep webuser /etc/shadowwebuser:$6$xxxx...hash...:19807:0:99999:7:::The file has 9 colon-separated fields:
| Field | Description |
|---|---|
| 1 | Username |
| 2 | Encrypted password (! or !! means the account is locked/has no password) |
| 3 | Date of last password change (days since 1970-01-01) |
| 4 | Minimum password age in days (0 means no restriction) |
| 5 | Maximum password age in days (99999 means never expires) |
| 6 | Number of warning days before password expiration |
| 7 | Number of days after password expiration before the account is disabled |
| 8 | Account expiration date |
| 9 | Reserved field |
/etc/group
Section titled “/etc/group”Stores group information, one group per line, with 4 fields:
group-name:password:GID:member-list$ grep wheel /etc/groupwheel:x:10:admin,deploy| Field | Example | Description |
|---|---|---|
| 1 | wheel | Group name |
| 2 | x | Group password (rarely used) |
| 3 | 10 | GID |
| 4 | admin,deploy | Group members (comma-separated) |
Password Policies and Expiration Management
Section titled “Password Policies and Expiration Management”View Password Expiration Information
Section titled “View Password Expiration Information”$ sudo chage -l webuserExample output:
Last password change : Mar 24, 2026Password expires : neverPassword inactive : neverAccount expires : neverMinimum number of days between password change : 0Maximum number of days between password change : 99999Number of days of warning before password expires : 7Set Password Expiration Policies
Section titled “Set Password Expiration Policies”$ sudo chage -M 90 webuser$ sudo chage -m 7 webuser$ sudo chage -W 14 webuser$ sudo chage -E 2026-12-31 tempuser$ sudo chage -d 0 webuserConfigure Global Default Password Policies
Section titled “Configure Global Default Password Policies”Global defaults are stored in /etc/login.defs:
$ grep -E "^PASS_" /etc/login.defsPASS_MAX_DAYS 99999PASS_MIN_DAYS 0PASS_MIN_LEN 5PASS_WARN_AGE 7Practical Example: Creating a Project Team
Section titled “Practical Example: Creating a Project Team”The following is a complete example demonstrating how to create users and groups for a project team.
-
Create the project group
Create the project group $ sudo groupadd project -
Create team members
Create users and add them to the project group $ sudo useradd -G project -c "Zhang San" zhangsan$ sudo useradd -G project -c "Li Si" lisi -
Set passwords for the users
Set passwords $ sudo passwd zhangsan$ sudo passwd lisi -
Configure password policies
Set 90-day password expiration $ sudo chage -M 90 zhangsan$ sudo chage -M 90 lisi -
Verify the configuration
Confirm user and group configuration is correct $ id zhangsanuid=1002(zhangsan) gid=1002(zhangsan) groups=1002(zhangsan),2001(project)$ getent group projectproject:x:2001:zhangsan,lisi
Common Issues
Section titled “Common Issues”What is the Difference Between useradd and adduser
Section titled “What is the Difference Between useradd and adduser”On EL systems, adduser is a symbolic link to useradd, and the two are identical:
$ ls -la /usr/sbin/adduserlrwxrwxrwx 1 root root 7 ... /usr/sbin/adduser -> useraddA User Cannot Log In
Section titled “A User Cannot Log In”Check the following:
$ sudo passwd -S webuserwebuser PS 2026-03-24 0 99999 7 -1 (Password set, SHA512 crypt.)Status field meanings: PS = Password set, LK = Locked, NP = No password.
$ grep webuser /etc/passwd | cut -d: -f7/bin/bashIf the shell is /sbin/nologin or /bin/false, the user cannot log in interactively.
How to List All Regular Users
Section titled “How to List All Regular Users”$ awk -F: '$3 >= 1000 && $3 < 65534 {print $1}' /etc/passwdFurther Reading
Section titled “Further Reading”- sudo Configuration — Configure administrator privileges
- File Permissions and ACLs — Manage file access permissions
man useradd/man usermod/man chage