Files
chemenu/kb/concepts/workflows/User Management.md
T
torben 7f74303a00
CI / verify (push) Successful in 52s
Release / release (push) Successful in 36s
kb/concepts/ bekommt Areas: layout: fuer concept, Area-Titel aus jedem Type-Spec, Schwellen-Empfehlung im lint (schliesst #59)
Files changed:
- CHANGES.md
- README.md
- VERSION
- kb/concepts/Ambient Environment Dependency.md
- kb/concepts/Anti-Cramming Heuristic.md
- kb/concepts/Audit Trail.md
- kb/concepts/BM25.md
- kb/concepts/Bulk Operations.md
- kb/concepts/CI Integration.md
- kb/concepts/COLLECTION.md
- kb/concepts/CPPC.md
- kb/concepts/Checkpoint Audit.md
- kb/concepts/Claude Code Auto Mode.md
- kb/concepts/Command Round-Trip Integrity.md
- kb/concepts/Confidence Scoring.md
- kb/concepts/Consolidation Tiers.md
- kb/concepts/Content Quality Control.md
- kb/concepts/Context Isolation.md
- kb/concepts/Contradiction Resolution.md
- kb/concepts/Cross-platform Agent Skills.md
- kb/concepts/Crystallization.md
- kb/concepts/Delete Rather Than Anonymize.md
- kb/concepts/Denylist over Allowlist.md
- kb/concepts/Detect-Repair Asymmetry.md
- kb/concepts/Diff-Reviewable Agent Edits.md
- kb/concepts/Dual Licensing by File Plan.md
- kb/concepts/Entity Extraction.md
- kb/concepts/Episodic Memory.md
- kb/concepts/Event-Driven Automation.md
- kb/concepts/Filter on Ingest.md
- kb/concepts/Forgetting.md
- kb/concepts/Graph Traversal.md
- kb/concepts/Green Suite Blind Spot.md
- kb/concepts/Hooks.md
- kb/concepts/Hybrid Search.md
- kb/concepts/INDEX.md
- kb/concepts/Implementation Spectrum.md
- kb/concepts/Index Scaling.md
- kb/concepts/Issue Label Scheme.md
- kb/concepts/Iteration and Cost Limits.md
- kb/concepts/KB Migration.md
- kb/concepts/KB Stack Versioning.md
- kb/concepts/Knowledge Compounding.md
- kb/concepts/Knowledge Graph.md
- kb/concepts/LLM Wiki Pattern.md
- kb/concepts/Lint Workflow.md
- kb/concepts/MCP-Leseserver.md
- kb/concepts/Mass-Update Gate.md
- kb/concepts/Memory Lifecycle.md
- kb/concepts/Mesh Sync.md
- kb/concepts/Modbus.md
- kb/concepts/Multi-Agent Collaboration.md
- kb/concepts/Naming Convention Conflict.md
- kb/concepts/OKF Compatibility.md
- kb/concepts/Optional Instance Context File.md
- kb/concepts/Personalization Plane.md
- kb/concepts/Privacy and Governance.md
- kb/concepts/Procedural Memory.md
- kb/concepts/Publish-Remote Gate.md
- kb/concepts/Quality Scoring.md
- kb/concepts/Quality and Self-Correction.md
- kb/concepts/RAG.md
- kb/concepts/Reciprocal Rank Fusion.md
- kb/concepts/SSD TRIM.md
- kb/concepts/Scale Ceiling.md
- kb/concepts/Self-Healing.md
- kb/concepts/Semantic Lint Automation.md
- kb/concepts/Semantic Memory.md
- kb/concepts/Session Orientation.md
- kb/concepts/Shared vs Private.md
- kb/concepts/Split Merge Reclassify.md
- kb/concepts/Split Threshold.md
- kb/concepts/Structural Enforcement over Documented Rule.md
- kb/concepts/Stub Threshold.md
- kb/concepts/Supersession.md
- kb/concepts/Three-Layer Architecture.md
- kb/concepts/Token Economics.md
- kb/concepts/Typed Relationships.md
- kb/concepts/User Management.md
- kb/concepts/Vector Search.md
- kb/concepts/Work Coordination.md
- kb/concepts/Workflow Extraction.md
- kb/concepts/Workflow Orchestration.md
- kb/concepts/Working Memory.md
- kb/concepts/Write-Once Frontmatter Fields.md
- kb/concepts/architectures/Consolidation Tiers.md
- kb/concepts/architectures/Context Isolation.md
- kb/concepts/architectures/Cross-platform Agent Skills.md
- kb/concepts/architectures/Episodic Memory.md
- kb/concepts/architectures/Hybrid Search.md
- kb/concepts/architectures/Implementation Spectrum.md
- kb/concepts/architectures/Knowledge Graph.md
- kb/concepts/architectures/LLM Wiki Pattern.md
- kb/concepts/architectures/MCP-Leseserver.md
- kb/concepts/architectures/Memory Lifecycle.md
- kb/concepts/architectures/OKF Compatibility.md
- kb/concepts/architectures/Optional Instance Context File.md
- kb/concepts/architectures/Personalization Plane.md
- kb/concepts/architectures/Procedural Memory.md
- kb/concepts/architectures/RAG.md
- kb/concepts/architectures/Scale Ceiling.md
- kb/concepts/architectures/Semantic Memory.md
- kb/concepts/architectures/Three-Layer Architecture.md
- kb/concepts/architectures/Token Economics.md
- kb/concepts/architectures/Working Memory.md
- kb/concepts/decisions/Delete Rather Than Anonymize.md
- kb/concepts/decisions/Denylist over Allowlist.md
- kb/concepts/decisions/Diff-Reviewable Agent Edits.md
- kb/concepts/decisions/Dual Licensing by File Plan.md
- kb/concepts/decisions/Issue Label Scheme.md
- kb/concepts/decisions/KB Stack Versioning.md
- kb/concepts/decisions/Structural Enforcement over Documented Rule.md
- kb/concepts/patterns/Audit Trail.md
- kb/concepts/patterns/BM25.md
- kb/concepts/patterns/Command Round-Trip Integrity.md
- kb/concepts/patterns/Confidence Scoring.md
- kb/concepts/patterns/Contradiction Resolution.md
- kb/concepts/patterns/Entity Extraction.md
- kb/concepts/patterns/Filter on Ingest.md
- kb/concepts/patterns/Forgetting.md
- kb/concepts/patterns/Graph Traversal.md
- kb/concepts/patterns/Mesh Sync.md
- kb/concepts/patterns/Quality Scoring.md
- kb/concepts/patterns/Reciprocal Rank Fusion.md
- kb/concepts/patterns/Self-Healing.md
- kb/concepts/patterns/Shared vs Private.md
- kb/concepts/patterns/Typed Relationships.md
- kb/concepts/patterns/Vector Search.md
- kb/concepts/patterns/Work Coordination.md
- kb/concepts/problems/Ambient Environment Dependency.md
- kb/concepts/problems/Detect-Repair Asymmetry.md
- kb/concepts/problems/Green Suite Blind Spot.md
- kb/concepts/problems/Naming Convention Conflict.md
- kb/concepts/problems/Write-Once Frontmatter Fields.md
- kb/concepts/protocols/CPPC.md
- kb/concepts/protocols/Modbus.md
- kb/concepts/protocols/SSD TRIM.md
- kb/concepts/workflows/Anti-Cramming Heuristic.md
- kb/concepts/workflows/Bulk Operations.md
- kb/concepts/workflows/CI Integration.md
- kb/concepts/workflows/Checkpoint Audit.md
- kb/concepts/workflows/Claude Code Auto Mode.md
- kb/concepts/workflows/Content Quality Control.md
- kb/concepts/workflows/Crystallization.md
- kb/concepts/workflows/Event-Driven Automation.md
- kb/concepts/workflows/Hooks.md
- kb/concepts/workflows/Index Scaling.md
- kb/concepts/workflows/Iteration and Cost Limits.md
- kb/concepts/workflows/KB Migration.md
- kb/concepts/workflows/Knowledge Compounding.md
- kb/concepts/workflows/Lint Workflow.md
- kb/concepts/workflows/Mass-Update Gate.md
- kb/concepts/workflows/Multi-Agent Collaboration.md
- kb/concepts/workflows/Privacy and Governance.md
- kb/concepts/workflows/Publish-Remote Gate.md
- kb/concepts/workflows/Quality and Self-Correction.md
- kb/concepts/workflows/Semantic Lint Automation.md
- kb/concepts/workflows/Session Orientation.md
- kb/concepts/workflows/Split Merge Reclassify.md
- kb/concepts/workflows/Split Threshold.md
- kb/concepts/workflows/Stub Threshold.md
- kb/concepts/workflows/Supersession.md
- kb/concepts/workflows/User Management.md
- kb/concepts/workflows/Workflow Extraction.md
- kb/concepts/workflows/Workflow Orchestration.md
- kb/index.md
- kb/log.md
- tools/CONTRACT.md
- tools/README.md
- tools/chemenu/catalog.py
- tools/chemenu/commands/index_build.py
- tools/chemenu/lint_core.py
- tools/chemenu/tests/conftest.py
- tools/chemenu/tests/test_cite_cmd.py
- tools/chemenu/tests/test_git_publish.py
- tools/chemenu/tests/test_index_build.py
- tools/chemenu/tests/test_lint.py
- tools/chemenu/tests/test_new_page.py
- tools/chemenu/tests/test_provenance.py
- tools/chemenu/tests/test_type_resolver.py
- tools/chemenu/tests/test_xref.py
- types/concept.md
- types/type-spec.md
2026-09-08 10:07:46 +02:00

7.2 KiB

type, concept_type, tags, created, modified, related, sources, confidence, confidence_base, provenance, summary
type concept_type tags created modified related sources confidence confidence_base provenance summary
types/concept.md workflow
linux
administration
security
users
groups
2026-07-31 2026-08-29
see-also
Arch Linux
see-also
AUR
see-also
Aura
see-also
makepkg
Source - Arch Linux Cheat Sheet
0.95 0.95 sourced Linux-Ablauf zum Anlegen, Ändern, Überwachen und Löschen von Benutzerkonten mit useradd, usermod und userdel, samt Gruppenverwaltung und sudoers-Konfiguration.

User Management

Typ: workflow

Definition

Benutzerverwaltung umfasst die Erstellung, Änderung, Überwachung und Löschung von Benutzerkonten auf einem Linux-System. Dies beinhaltet die Verwaltung von Passwörtern, Gruppenmitgliedschaften, Berechtigungen und Kontostatus (gesperrt/entsperrt, aktiviert/deaktiviert).

Kernpunkte

  • Kernwerkzeuge: useradd, usermod, userdel, passwd
  • Konfiguration: /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers
  • Kontostatus: Aktiv, gesperrt, abgelaufen, deaktiviert
  • Best Practice: Principle of least privilege

Sperrung von Konten

Die Sperrung eines Benutzerkontos verhindert die kennwortbasierte Authentifizierung, während das Konto und seine Dateien erhalten bleiben. Das Konto kann später ohne Datenverlust entsperrt werden.

Methoden zum Sperren von Konten

Methode 1: usermod (Empfohlen)

# Lock an account
sudo usermod -L username

# Unlock an account
sudo usermod -U username

Was passiert: Fügt das Präfix ! zum Passwort-Hash in /etc/shadow hinzu

Methode 2: passwd

# Lock an account
sudo passwd -l username

# Unlock an account
sudo passwd -u username

Was passiert: Gleiches wie usermod -L, fügt das Präfix ! zum Passwort hinzu

Sperrstatus überprüfen

# Check if user account is locked
passwd --status username

Beispielausgabe:

username LK 2026-07-31 0 99999 7 -1 (Password set, SHA512 crypt.)

Das Flag LK zeigt Gesperrtes Konto an (Passwort gesperrt).

Alle Benutzer überprüfen

# List all users with account status
passwd -a --status

# Alternative: check /etc/shadow
sudo grep '^username:' /etc/shadow

Format für gesperrtes Passwort: Präfix ! oder !! im zweiten Feld von /etc/shadow

Benutzer erstellen

Einfache Benutzererstellung

# Create user with home directory
sudo useradd -m username

# Set password
sudo passwd username

# Create user with custom home, shell, and comment
sudo useradd -m -d /home/customdir -s /bin/bash -c "Full Name" username

Benutzer mit Ablaufdatum erstellen

# Create user that expires on specific date
sudo useradd -e 2026-12-31 username

# Modify expiry of existing user
sudo usermod -e 2026-12-31 username

Massenerstellung von Benutzern

# Create multiple users
for user in user1 user2 user3; do
  sudo useradd -m $user
  sudo passwd $user
done

Benutzer löschen

Benutzer entfernen (Home-Verzeichnis behalten)

sudo userdel username

Benutzer und Home-Verzeichnis entfernen

sudo userdel -r username

Erzwungenes Löschen (Benutzer ist angemeldet)

# Kill user processes first
sudo pkill -u username
sudo pkill -9 -u username

# Then delete
sudo userdel -r -f username

Gruppenverwaltung

Gruppen erstellen und verwalten

# Create group
sudo groupadd groupname

# Add user to group
sudo usermod -aG groupname username

# Remove user from group
sudo gpasswd -d username groupname

# Delete group
sudo groupdel groupname

Primäre vs. ergänzende Gruppen

  • Primäre Gruppe: Wird bei Anmeldung gesetzt, Standard für neue Dateien
  • Ergänzende Gruppen: Zusätzliche Gruppenmitgliedschaften
# Set primary group
sudo usermod -g primarygroup username

# Add to supplementary group
sudo usermod -aG supplementarygroup username

Sudo-Konfiguration

Benutzer zu Sudoers hinzufügen

# Add to wheel group (most distributions)
sudo usermod -aG wheel username

# Manual sudoers entry
sudo visudo
# Add line: username ALL=(ALL) ALL

Passwortloses Sudo

# Add to sudoers with NOPASSWD
sudo visudo
# Add line: username ALL=(ALL) NOPASSWD: ALL

# For CI/CD containers (example from [[Arch Linux]] page)
echo "builder ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers

Passwortverwaltung

Passwort ändern

# Change own password
passwd

# Change another user's password (requires sudo)
sudo passwd username

Erzwinge Passwortänderung beim nächsten Anmelden

sudo passwd -e username

Passwortrichtlinien

Konfigurieren in /etc/login.defs:

  • PASS_MAX_DAYS - Maximales Paswortalter
  • PASS_MIN_DAYS - Minimales Paswortalter
  • PASS_MIN_LEN - Minimale Passwortlänge

Benutzer überwachen

Angemeldete Benutzer auflisten

# Show logged in users
who

# Show with more details
w

# Show login history
last

# Show user processes
ps -u username

Anmeldestatus des Benutzers überprüfen

# Check when user last logged in
lastlog | grep username

# Check user's login shell
getent passwd username | cut -d: -f7

Kontoablauf

Ablauf überprüfen

# Check when account expires
chage -l username

# Check via /etc/shadow (field 8 = expiry date)
sudo grep username /etc/shadow | cut -d: -f8

Ablauf einstellen

# Set expiry date (YYYY-MM-DD)
sudo chage -E 2026-12-31 username

# Set password expiry (days until must change)
sudo chage -M 90 username

Deaktivieren vs. Sperren

Aktion Methode Umkehrbar Erhält Dateien Erhält UID/GID
Sperren usermod -L oder passwd -l Ja Ja Ja
Deaktivieren usermod --expiredate 1 Ja Ja Ja
Löschen userdel Nein Vielleicht (mit -r) Nein

Best Practices

  1. Gruppen verwenden: Berechtigungen über Gruppen verwalten, nicht über einzelne Benutzer
  2. Least Privilege: Nur notwendige Berechtigungen erteilen
  3. Kontobereinigung: Regelmäßig ungenutzte Konten entfernen
  4. Passwortrichtlinien: Starke Passwörter und Rotation erzwingen
  5. Audit-Protokolle: Benutzeraktivitätsprotokolle überwachen
  6. Sudoers sichern: Immer visudo verwenden, nie direkt bearbeiten
  7. SSH-Schlüssel: SSH-Schlüsselverwaltung gegenüber Passwörtern bevorzugen

Häufige Probleme

Benutzer kann sich nicht anmelden

# Check account status
passwd -S username

# Check if locked
passwd --status username | grep LK

# Check if expired
chage -l username | grep "Account expires"

# Check if shell is valid
getent passwd username | cut -d: -f7

Berechtigung verweigert

# Check group membership
groups username

# Check file permissions
ls -la /path/to/file

# Check effective permissions
sudo -u username test -r /path/to/file

Beziehungen

Siehe auch

Beziehungen