CHEAT SHEET
Users & permissions cheat sheet
Accounts, groups, permissions, ACLs and sudo. The access-control commands you need on RHEL.
Accounts
useradd -m -s /bin/bash alice # user with a home folder and shelluseradd -m -G wheel,devs alice # with extra groupspasswd alice # set the passwordusermod -aG devs alice # add to a group (-a keeps the others)usermod -L alice # lock the accountusermod -U alice # unlock itusermod -s /sbin/nologin alice # no interactive loginuserdel -r alice # delete the user and the home folderid alice # UID, GID and groupsgetent passwd alice # the account entry
Groups
groupadd devs # create a groupgroupdel devs # delete itgpasswd -d alice devs # remove a user from a groupgroups alice # groups of a user
Password aging
chage -l alice # show the aging settingschage -M 90 -W 7 alice # expire in 90 days, warn 7 days beforechage -E 2027-01-01 alice # the account expires on a datechage -d 0 alice # force a change at next login
Permissions
chmod 640 file # numeric modechmod u+x,g-w,o-rwx file # symbolic modechmod -R 755 dir # recursivechown alice:devs file # owner and groupchown -R alice: dir # recursive, owner only (group stays)chgrp devs file # group onlyumask # show the default maskumask 027 # new files 640, new folders 750
| Number | Permission |
|---|---|
| 4 | r: read |
| 2 | w: write |
| 1 | x: execute |
| 7 6 5 4 | rwx, rw-, r-x, r-- |
Special bits
| Mode | Meaning |
|---|---|
| 4000 (u+s) | setuid: run a file as its owner |
| 2000 (g+s) | setgid: files in a folder inherit its group |
| 1000 (+t) | sticky: only the owner can delete files in the folder |
chmod 2775 /shared # a shared team folderchmod +t /tmp/drop # sticky bitchmod u+s /usr/local/bin/tool # setuid
ACLs
setfacl -m u:bob:rw file # give one user accesssetfacl -m g:devs:rx dir # give one group accesssetfacl -R -m u:bob:rx dir # recursivelysetfacl -d -m g:devs:rwx dir # default ACL for new files in a foldersetfacl -x u:bob file # remove one entrysetfacl -b file # remove all ACLsgetfacl file # show the ACL
sudo
visudo # edit sudo rules safelysudo -l # what can I run?sudo -u alice command # run as another usersudo -i # root login shellsu - alice # switch user with a login shell
# /etc/sudoers.d/alicealice ALL=(ALL) NOPASSWD: ALL%wheel ALL=(ALL) ALL
More cheat sheets
Questions
How do I add a user to a group without removing other groups?
Use usermod -aG group user. Without -a the user would be removed from every other supplementary group.
What does chmod 2775 do on a directory?
It sets the setgid bit (2) so new files inherit the directory's group, and gives rwx to the owner and group and r-x to others.
How do I give one extra user access to a file?
Use an ACL: setfacl -m u:bob:rw file. Read it back with getfacl file.
How do I force a password change at next login?
Run chage -d 0 username. The user must set a new password the next time they log in.