The account commands you learned all read and write a handful of plain-text files. Knowing their formats lets you audit accounts quickly, spot misconfigurations and answer exam questions that show you a raw line and ask what it means. Each file is colon-separated, one record per line, which makes them easy to query with cut, awk and grep. /etc/passwd holds one line per account with seven fields: username, password placeholder, UID, GID (primary group), GECOS comment, home directory and login shell. For example, alice:x:1001:1001:Alice Ng:/home/alice:/bin/bash. The x means the real password hash is stored in /etc/shadow. The file must be world-readable, because many programs map UIDs to names, which is exactly why hashes were moved out of it. UID 0 is root; system accounts use low UIDs, and regular users start at a threshold set in /etc/login.defs (commonly 1000). A shell of /sbin/nologin or /usr/sbin/nologin prevents interactive logins for service accounts.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.