Files changed: - CHANGES.md - README.md - VERSION - kb/concepts/Ambient Environment Dependency.md - kb/concepts/Anti-Cramming Heuristic.md - kb/concepts/Audit Trail.md - kb/concepts/BM25.md - kb/concepts/Bulk Operations.md - kb/concepts/CI Integration.md - kb/concepts/COLLECTION.md - kb/concepts/CPPC.md - kb/concepts/Checkpoint Audit.md - kb/concepts/Claude Code Auto Mode.md - kb/concepts/Command Round-Trip Integrity.md - kb/concepts/Confidence Scoring.md - kb/concepts/Consolidation Tiers.md - kb/concepts/Content Quality Control.md - kb/concepts/Context Isolation.md - kb/concepts/Contradiction Resolution.md - kb/concepts/Cross-platform Agent Skills.md - kb/concepts/Crystallization.md - kb/concepts/Delete Rather Than Anonymize.md - kb/concepts/Denylist over Allowlist.md - kb/concepts/Detect-Repair Asymmetry.md - kb/concepts/Diff-Reviewable Agent Edits.md - kb/concepts/Dual Licensing by File Plan.md - kb/concepts/Entity Extraction.md - kb/concepts/Episodic Memory.md - kb/concepts/Event-Driven Automation.md - kb/concepts/Filter on Ingest.md - kb/concepts/Forgetting.md - kb/concepts/Graph Traversal.md - kb/concepts/Green Suite Blind Spot.md - kb/concepts/Hooks.md - kb/concepts/Hybrid Search.md - kb/concepts/INDEX.md - kb/concepts/Implementation Spectrum.md - kb/concepts/Index Scaling.md - kb/concepts/Issue Label Scheme.md - kb/concepts/Iteration and Cost Limits.md - kb/concepts/KB Migration.md - kb/concepts/KB Stack Versioning.md - kb/concepts/Knowledge Compounding.md - kb/concepts/Knowledge Graph.md - kb/concepts/LLM Wiki Pattern.md - kb/concepts/Lint Workflow.md - kb/concepts/MCP-Leseserver.md - kb/concepts/Mass-Update Gate.md - kb/concepts/Memory Lifecycle.md - kb/concepts/Mesh Sync.md - kb/concepts/Modbus.md - kb/concepts/Multi-Agent Collaboration.md - kb/concepts/Naming Convention Conflict.md - kb/concepts/OKF Compatibility.md - kb/concepts/Optional Instance Context File.md - kb/concepts/Personalization Plane.md - kb/concepts/Privacy and Governance.md - kb/concepts/Procedural Memory.md - kb/concepts/Publish-Remote Gate.md - kb/concepts/Quality Scoring.md - kb/concepts/Quality and Self-Correction.md - kb/concepts/RAG.md - kb/concepts/Reciprocal Rank Fusion.md - kb/concepts/SSD TRIM.md - kb/concepts/Scale Ceiling.md - kb/concepts/Self-Healing.md - kb/concepts/Semantic Lint Automation.md - kb/concepts/Semantic Memory.md - kb/concepts/Session Orientation.md - kb/concepts/Shared vs Private.md - kb/concepts/Split Merge Reclassify.md - kb/concepts/Split Threshold.md - kb/concepts/Structural Enforcement over Documented Rule.md - kb/concepts/Stub Threshold.md - kb/concepts/Supersession.md - kb/concepts/Three-Layer Architecture.md - kb/concepts/Token Economics.md - kb/concepts/Typed Relationships.md - kb/concepts/User Management.md - kb/concepts/Vector Search.md - kb/concepts/Work Coordination.md - kb/concepts/Workflow Extraction.md - kb/concepts/Workflow Orchestration.md - kb/concepts/Working Memory.md - kb/concepts/Write-Once Frontmatter Fields.md - kb/concepts/architectures/Consolidation Tiers.md - kb/concepts/architectures/Context Isolation.md - kb/concepts/architectures/Cross-platform Agent Skills.md - kb/concepts/architectures/Episodic Memory.md - kb/concepts/architectures/Hybrid Search.md - kb/concepts/architectures/Implementation Spectrum.md - kb/concepts/architectures/Knowledge Graph.md - kb/concepts/architectures/LLM Wiki Pattern.md - kb/concepts/architectures/MCP-Leseserver.md - kb/concepts/architectures/Memory Lifecycle.md - kb/concepts/architectures/OKF Compatibility.md - kb/concepts/architectures/Optional Instance Context File.md - kb/concepts/architectures/Personalization Plane.md - kb/concepts/architectures/Procedural Memory.md - kb/concepts/architectures/RAG.md - kb/concepts/architectures/Scale Ceiling.md - kb/concepts/architectures/Semantic Memory.md - kb/concepts/architectures/Three-Layer Architecture.md - kb/concepts/architectures/Token Economics.md - kb/concepts/architectures/Working Memory.md - kb/concepts/decisions/Delete Rather Than Anonymize.md - kb/concepts/decisions/Denylist over Allowlist.md - kb/concepts/decisions/Diff-Reviewable Agent Edits.md - kb/concepts/decisions/Dual Licensing by File Plan.md - kb/concepts/decisions/Issue Label Scheme.md - kb/concepts/decisions/KB Stack Versioning.md - kb/concepts/decisions/Structural Enforcement over Documented Rule.md - kb/concepts/patterns/Audit Trail.md - kb/concepts/patterns/BM25.md - kb/concepts/patterns/Command Round-Trip Integrity.md - kb/concepts/patterns/Confidence Scoring.md - kb/concepts/patterns/Contradiction Resolution.md - kb/concepts/patterns/Entity Extraction.md - kb/concepts/patterns/Filter on Ingest.md - kb/concepts/patterns/Forgetting.md - kb/concepts/patterns/Graph Traversal.md - kb/concepts/patterns/Mesh Sync.md - kb/concepts/patterns/Quality Scoring.md - kb/concepts/patterns/Reciprocal Rank Fusion.md - kb/concepts/patterns/Self-Healing.md - kb/concepts/patterns/Shared vs Private.md - kb/concepts/patterns/Typed Relationships.md - kb/concepts/patterns/Vector Search.md - kb/concepts/patterns/Work Coordination.md - kb/concepts/problems/Ambient Environment Dependency.md - kb/concepts/problems/Detect-Repair Asymmetry.md - kb/concepts/problems/Green Suite Blind Spot.md - kb/concepts/problems/Naming Convention Conflict.md - kb/concepts/problems/Write-Once Frontmatter Fields.md - kb/concepts/protocols/CPPC.md - kb/concepts/protocols/Modbus.md - kb/concepts/protocols/SSD TRIM.md - kb/concepts/workflows/Anti-Cramming Heuristic.md - kb/concepts/workflows/Bulk Operations.md - kb/concepts/workflows/CI Integration.md - kb/concepts/workflows/Checkpoint Audit.md - kb/concepts/workflows/Claude Code Auto Mode.md - kb/concepts/workflows/Content Quality Control.md - kb/concepts/workflows/Crystallization.md - kb/concepts/workflows/Event-Driven Automation.md - kb/concepts/workflows/Hooks.md - kb/concepts/workflows/Index Scaling.md - kb/concepts/workflows/Iteration and Cost Limits.md - kb/concepts/workflows/KB Migration.md - kb/concepts/workflows/Knowledge Compounding.md - kb/concepts/workflows/Lint Workflow.md - kb/concepts/workflows/Mass-Update Gate.md - kb/concepts/workflows/Multi-Agent Collaboration.md - kb/concepts/workflows/Privacy and Governance.md - kb/concepts/workflows/Publish-Remote Gate.md - kb/concepts/workflows/Quality and Self-Correction.md - kb/concepts/workflows/Semantic Lint Automation.md - kb/concepts/workflows/Session Orientation.md - kb/concepts/workflows/Split Merge Reclassify.md - kb/concepts/workflows/Split Threshold.md - kb/concepts/workflows/Stub Threshold.md - kb/concepts/workflows/Supersession.md - kb/concepts/workflows/User Management.md - kb/concepts/workflows/Workflow Extraction.md - kb/concepts/workflows/Workflow Orchestration.md - kb/index.md - kb/log.md - tools/CONTRACT.md - tools/README.md - tools/chemenu/catalog.py - tools/chemenu/commands/index_build.py - tools/chemenu/lint_core.py - tools/chemenu/tests/conftest.py - tools/chemenu/tests/test_cite_cmd.py - tools/chemenu/tests/test_git_publish.py - tools/chemenu/tests/test_index_build.py - tools/chemenu/tests/test_lint.py - tools/chemenu/tests/test_new_page.py - tools/chemenu/tests/test_provenance.py - tools/chemenu/tests/test_type_resolver.py - tools/chemenu/tests/test_xref.py - types/concept.md - types/type-spec.md
7.2 KiB
type, concept_type, tags, created, modified, related, sources, confidence, confidence_base, provenance, summary
| type | concept_type | tags | created | modified | related | sources | confidence | confidence_base | provenance | summary | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| types/concept.md | workflow |
|
2026-07-31 | 2026-08-29 |
|
|
0.95 | 0.95 | sourced | Linux-Ablauf zum Anlegen, Ändern, Überwachen und Löschen von Benutzerkonten mit useradd, usermod und userdel, samt Gruppenverwaltung und sudoers-Konfiguration. |
User Management
Typ: workflow
Definition
Benutzerverwaltung umfasst die Erstellung, Änderung, Überwachung und Löschung von Benutzerkonten auf einem Linux-System. Dies beinhaltet die Verwaltung von Passwörtern, Gruppenmitgliedschaften, Berechtigungen und Kontostatus (gesperrt/entsperrt, aktiviert/deaktiviert).
Kernpunkte
- Kernwerkzeuge:
useradd,usermod,userdel,passwd - Konfiguration:
/etc/passwd,/etc/shadow,/etc/group,/etc/sudoers - Kontostatus: Aktiv, gesperrt, abgelaufen, deaktiviert
- Best Practice: Principle of least privilege
Sperrung von Konten
Die Sperrung eines Benutzerkontos verhindert die kennwortbasierte Authentifizierung, während das Konto und seine Dateien erhalten bleiben. Das Konto kann später ohne Datenverlust entsperrt werden.
Methoden zum Sperren von Konten
Methode 1: usermod (Empfohlen)
# Lock an account
sudo usermod -L username
# Unlock an account
sudo usermod -U username
Was passiert: Fügt das Präfix ! zum Passwort-Hash in /etc/shadow hinzu
Methode 2: passwd
# Lock an account
sudo passwd -l username
# Unlock an account
sudo passwd -u username
Was passiert: Gleiches wie usermod -L, fügt das Präfix ! zum Passwort hinzu
Sperrstatus überprüfen
# Check if user account is locked
passwd --status username
Beispielausgabe:
username LK 2026-07-31 0 99999 7 -1 (Password set, SHA512 crypt.)
Das Flag LK zeigt Gesperrtes Konto an (Passwort gesperrt).
Alle Benutzer überprüfen
# List all users with account status
passwd -a --status
# Alternative: check /etc/shadow
sudo grep '^username:' /etc/shadow
Format für gesperrtes Passwort: Präfix ! oder !! im zweiten Feld von /etc/shadow
Benutzer erstellen
Einfache Benutzererstellung
# Create user with home directory
sudo useradd -m username
# Set password
sudo passwd username
# Create user with custom home, shell, and comment
sudo useradd -m -d /home/customdir -s /bin/bash -c "Full Name" username
Benutzer mit Ablaufdatum erstellen
# Create user that expires on specific date
sudo useradd -e 2026-12-31 username
# Modify expiry of existing user
sudo usermod -e 2026-12-31 username
Massenerstellung von Benutzern
# Create multiple users
for user in user1 user2 user3; do
sudo useradd -m $user
sudo passwd $user
done
Benutzer löschen
Benutzer entfernen (Home-Verzeichnis behalten)
sudo userdel username
Benutzer und Home-Verzeichnis entfernen
sudo userdel -r username
Erzwungenes Löschen (Benutzer ist angemeldet)
# Kill user processes first
sudo pkill -u username
sudo pkill -9 -u username
# Then delete
sudo userdel -r -f username
Gruppenverwaltung
Gruppen erstellen und verwalten
# Create group
sudo groupadd groupname
# Add user to group
sudo usermod -aG groupname username
# Remove user from group
sudo gpasswd -d username groupname
# Delete group
sudo groupdel groupname
Primäre vs. ergänzende Gruppen
- Primäre Gruppe: Wird bei Anmeldung gesetzt, Standard für neue Dateien
- Ergänzende Gruppen: Zusätzliche Gruppenmitgliedschaften
# Set primary group
sudo usermod -g primarygroup username
# Add to supplementary group
sudo usermod -aG supplementarygroup username
Sudo-Konfiguration
Benutzer zu Sudoers hinzufügen
# Add to wheel group (most distributions)
sudo usermod -aG wheel username
# Manual sudoers entry
sudo visudo
# Add line: username ALL=(ALL) ALL
Passwortloses Sudo
# Add to sudoers with NOPASSWD
sudo visudo
# Add line: username ALL=(ALL) NOPASSWD: ALL
# For CI/CD containers (example from [[Arch Linux]] page)
echo "builder ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers
Passwortverwaltung
Passwort ändern
# Change own password
passwd
# Change another user's password (requires sudo)
sudo passwd username
Erzwinge Passwortänderung beim nächsten Anmelden
sudo passwd -e username
Passwortrichtlinien
Konfigurieren in /etc/login.defs:
PASS_MAX_DAYS- Maximales PaswortalterPASS_MIN_DAYS- Minimales PaswortalterPASS_MIN_LEN- Minimale Passwortlänge
Benutzer überwachen
Angemeldete Benutzer auflisten
# Show logged in users
who
# Show with more details
w
# Show login history
last
# Show user processes
ps -u username
Anmeldestatus des Benutzers überprüfen
# Check when user last logged in
lastlog | grep username
# Check user's login shell
getent passwd username | cut -d: -f7
Kontoablauf
Ablauf überprüfen
# Check when account expires
chage -l username
# Check via /etc/shadow (field 8 = expiry date)
sudo grep username /etc/shadow | cut -d: -f8
Ablauf einstellen
# Set expiry date (YYYY-MM-DD)
sudo chage -E 2026-12-31 username
# Set password expiry (days until must change)
sudo chage -M 90 username
Deaktivieren vs. Sperren
| Aktion | Methode | Umkehrbar | Erhält Dateien | Erhält UID/GID |
|---|---|---|---|---|
| Sperren | usermod -L oder passwd -l |
Ja | Ja | Ja |
| Deaktivieren | usermod --expiredate 1 |
Ja | Ja | Ja |
| Löschen | userdel |
Nein | Vielleicht (mit -r) | Nein |
Best Practices
- Gruppen verwenden: Berechtigungen über Gruppen verwalten, nicht über einzelne Benutzer
- Least Privilege: Nur notwendige Berechtigungen erteilen
- Kontobereinigung: Regelmäßig ungenutzte Konten entfernen
- Passwortrichtlinien: Starke Passwörter und Rotation erzwingen
- Audit-Protokolle: Benutzeraktivitätsprotokolle überwachen
- Sudoers sichern: Immer
visudoverwenden, nie direkt bearbeiten - SSH-Schlüssel: SSH-Schlüsselverwaltung gegenüber Passwörtern bevorzugen
Häufige Probleme
Benutzer kann sich nicht anmelden
# Check account status
passwd -S username
# Check if locked
passwd --status username | grep LK
# Check if expired
chage -l username | grep "Account expires"
# Check if shell is valid
getent passwd username | cut -d: -f7
Berechtigung verweigert
# Check group membership
groups username
# Check file permissions
ls -la /path/to/file
# Check effective permissions
sudo -u username test -r /path/to/file
Beziehungen
Siehe auch
- Source - Arch Linux Cheat Sheet
- https://wiki.archlinux.org/title/Users_and_groups
- https://www.thegeekdiary.com/unix-linux-how-to-lock-or-disable-an-user-account/
Beziehungen
- see-also: Arch Linux
- see-also: AUR
- see-also: Aura
- see-also: makepkg