# Linux basics - Tutorial 2[redhat]

#### Redhat Linux Basics - Tutorial 2.

After going through this you will be comfortable in Linux user, group management and setting permissions of read write execute for files and directories.

#### Let's start by understanding what are the different kinds of permissions we have and how to set them to files and folders

#### Different permissions we have in Linux ?

*   Read(r) - represented by number 4
    
*   Write(w) - represented by number 2
    
*   Execute(x) - represented by number 1
    
*   No permission - represented by 0
    

#### Let us see how to long details about the files and folders and understand which is permissions are all about

To **long list** files and folders use **ll**

```bash
ll
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 7.12.25 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/8a5875b1-f289-496c-a4a5-0c0f456f4f4a.png align="center")

If you see in the above picture we have many files and folders. Let us take two of them to understand the concept. Focus on newfolder directory and file1.txt file.

*   drwxr-xr-x. 2 ec2-user ec2-user 6 Jul 27 15:10 newfolder
    
*   rwxr--rwx. 1 ec2-user ec2-user 0 Jul 26 15:54 file1.txt
    

*Did you see for the* ***newfolder*** *directory we have* ***drwxr-xr-x***. The **d** here denotes it is a directory. And if you see for the file file1.txt we do not have a ***d***, this means it is a file. All the other spots shows if there is read write and execute permissions present or not. Now let us understand about these permissions.

So we have something like this here.

drwxr-xr-x. (Understanding permissions from **newfolder directory**) Just ignore the *d* here , we all know it indicates that this is a directory. Rest are permissions and we should divide them in 3 parts.

1.  In 1st part we have, rwx - This part is for *user owner(u)*. This indicates that the *user owner* here has read(r) write(w) and execute(x) permissions for the directory **newfolder**
    
2.  In 2nd part we have, r-x - This part is for *group(g)* of this file or directory. This indicates that the *group or any users in this group* here has only read(r) and execute(x) permissions for the directory **newfolder**
    
3.  In 3rd part we also have, r-x - This part is for *other users(o)*. This indicates that the *other users that means users who are not owner of this file* here also has only read(r) and execute(x) permissions for the directory **newfolder**
    

**Quick Challenge**: Answer by yourself what permissions does the user(u), group(g) and other(o) users have for the file "file1.txt"

#### Let's learn how to set different permissions for file1.txt

To change permissions for **user(u)** use "chmod"

```bash
chmod u-x file1.txt #this removes execute permission for user
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 7.53.21 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/62dfe0d9-bc79-4ac3-92a5-71fe55da5451.png align="center")

Now add back the **execute** permission for the users owner for file1.txt

```bash
chmod u+x file1.txt #this adds the execute permission 
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 7.57.12 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/e0eacc80-0e28-47b7-aff7-df7ed0b7b870.png align="center")

**Note:** You can set permissions like this or with the numerical method as shown below.

Let us do this for file1.txt , but before that we need to understand how to calculate the permission. Let us give

*   read, write,execute for users = 4 + 2 + 1 = 7
    
*   no permission for groups = 0
    
*   only execute permissions for other users = 0 + 0 + 1 =1
    

So our total is something like this 701. Here 7 is for users,0 is for groups and 1 is for other users.

To change permissions with number use the command below

```bash
chmod 701 file1.txt 
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.03.29 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/dca743f6-29ae-4c03-8c65-b38c8c7ccb54.png align="center")

**Note:** Now that you know how to change permissions for file1.txt try to change permissions for the folder newfolder.

### Now let us move to user and group management

# What is a User?

A **user** is an account that can log in to the Linux system and perform tasks.

Every command you execute runs as a specific user.

### Examples of Users

*   `root`
    
*   `ec2-user`
    
*   `developer`
    
*   `jenkins`
    
*   `nginx`
    

In production environments, applications typically run as **dedicated users** instead of the **root** user to improve security.

For example:

*   Jenkins runs as the **jenkins** user.
    
*   Nginx runs as the **nginx** user.
    
*   Apache runs as the **apache** user.
    

* * *

# What is a User ID (UID)?

Every user in Linux is assigned a **User ID (UID)**, which is a unique numeric identifier.

Linux internally identifies users by their **UID** rather than by their username.

To **add** a new user

```bash
useradd happyuser
id happyuser #shows all details about happyuser
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.24.35 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/0cafd4b6-9ca7-42e2-a78f-1de1485f6ab3.png align="center")

Note: Whenever a new user is created, a primary group with the same name as user is also created. Thus we can see the username with uid, primary group name with group id(gid) and which groups this user belong to. And long with these new entries are made about this user and groups in /etc/passwd file, /etc/shadow file, /etc/group file and /etc/gshadow file. You can login as a root user and see all the contents of this file if you want.

Now let's **add** a new user and see how to delete this user

```bash
useradd unhappyuser
id unhappyuser #shows all details about unhappyuser
userdel unhappyuser
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.29.56 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/86a69422-6cab-4e38-af78-c919d07055ae.png align="center")

To **see** which user you are currrently logged-in as type

```bash
whoami
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.31.56 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/bb7be796-24e9-4f42-9c3f-a8466fc270b0.png align="center")

Now we are logged in as a root user. Let us **switch** to happyuser

```bash
su - happyuser
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.36.08 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/253a1092-fca2-4ec3-9849-b8bea215f0d4.png align="center")

To **logout** of the current user type

```bash
logout
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.37.55 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/d710f8e7-19ce-440d-a5bf-53db7309e75d.png align="center")

To set **password** for a user, switch to root user or a user who has admin priviledges, then type

```bash
passwd happyuser
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.06.52 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/c5b7b920-5212-4f26-ba48-555b4b508e72.png align="center")

**Note:** To check the password of the user in encrypted form you can see the contents of /etc/shadow file

Now let us add 3 more users here

```bash
useradd hitesh
useradd jitendra
useradd lola
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.41.37 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/860f8e4f-58f2-4514-9c78-d2b1510df5dd.png align="center")

# What is a Group?

A **group** is a collection of users.

Instead of assigning permissions to each user individually, Linux allows you to assign permissions to a group.

For example, imagine you have five developers working on the same project.

Instead of giving permissions to each developer separately, you can create a group called **developers** and add all five users to that group.

Any permission assigned to the group automatically applies to every member.

This makes administration much simpler and more efficient.

* * *

# What is a Group ID (GID)?

Every group has a unique numeric identifier called a **Group ID (GID)**.

Just like users have UIDs, groups have GIDs.

To **add** a new group

```bash
groupadd devops
groupadd testers
groupadd dancers
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.46.27 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/8fb5fb74-1ff6-4bd0-bbc5-785c683369ab.png align="center")

To **delete** a group, type

```bash
groupdel devops
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.47.49 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/71485097-2b1a-44a3-b894-dca3caed0044.png align="center")

To **add** users to a group, type

```bash
usermod -aG dancers hitesh
usermod -aG testers hitesh
usermod -aG dancers jitendra
id jitendra # check the user details
id hitesh # check the user details
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 8.52.02 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/a159e4a9-6acb-4465-9c38-c2c56f3fa327.png align="center")

I would like you to see the difference between both the commands mentioned below. Please have a look to become an expert 😎 here

```text
usermod -g <groupname> <username>
usermod -aG <groupname> <username>
```

## Types of groups

*   Primary group
    
*   Secondary Group
    

# What is a Primary Group?

Every user must belong to exactly **one primary group**.

The primary group is assigned when the user is created.

Whenever the user creates a new file or directory, Linux automatically assigns the file to the user's primary group.

# What are Secondary Groups?

A user can belong to multiple additional groups called **secondary groups**.

These groups provide additional permissions without changing the user's primary group.

This allows one user to perform multiple roles.

# Why Do We Use Groups?

Imagine a company with **100 developers**.

Without groups, you would need to grant permissions individually to all 100 users.

Whenever a new developer joins, you would repeat the same process.

Instead, you create a single **developers** group and assign permissions once.

Every member automatically receives the same permissions.

Groups make permission management **scalable**, **simpler**, and **easier to maintain**.

**Please pay your attention here guys, the most important group in Redhat linux**

# What is the Wheel Group?

The **wheel** group is a special administrative group in Linux that allows its members to execute commands with **root (administrator) privileges** using the `sudo` command.

Instead of logging in as the `root` user, Linux recommends adding trusted users to the **wheel** group so they can perform administrative tasks securely.

This follows the **principle of least privilege**, where users operate with normal permissions and only elevate privileges when necessary.

* * *

# Why is the Wheel Group Important?

Using the **wheel** group improves both **security** and **accountability**.

Instead of everyone sharing the root account:

*   Each administrator has their own user account.
    
*   Administrative actions are performed using `sudo`.
    
*   Every command executed with `sudo` is logged.
    
*   The root account remains protected.
    

This makes it easier to track who performed administrative actions on the system.

Let's **add** users to hitesh to the wheel group to give authorize him to perform admin function i.e. execute sudo commands

```bash
usermod -aG wheel hitesh
id hitesh # check the user details
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.01.05 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/c7185440-dc35-4d8f-bd78-99a3e5a37bec.png align="center")

* * *

### User database files

*   passwd - stores the users information
    
*   Shadow file - stores the user’s password information
    
*   Group file - stores group information
    
*   gshadow - stores group password information
    

If you do not have any of the 4 files in your system , it will be corrupted Location of all files - /etc/

```text

How to read passwd file ?
Location - /etc/passwd
File content - root:x:0:0:root/root:/bin/bash

7 colon separated field
1. Username
2. Password pointer
3. Uid
4. Gid
5. Comment section /gecos field
6. Home directory
7. Shell name 

How to read shadow file ?
Location - /etc/shadow
File content - maxich:$y$j9T$aUZfhDfgGPlW.PtmcyxnG0$WFo2t5uRCCsq5ZTGKyhzjfkXz793RldC2lABZG5hLr7:20640:0:99999:7:::

9 colon separated field
1. Username
2. User’s password in encrypted form
3. Last password change date
4. Minimum password change limit
5. Maximum password change limit
6. Warning period(days)
7. Inactivity
8. Account expiry
9. Blank and reserved for future use
   How to read group file ?
Location - /etc/group
File content - maxich:x:1001:maxich

4 colon separated field
1. Group name
2. Password pointer
3. Group ID
4. Group member name

How to read gshadow file ?
Location - /etc/gshadow
File content - systemd-journal:!*::ec2-user

4 colon separated field
1. Group name
2. Password in encrypted form
3. Group admin name
4. Group member information

```

# What is ACL (Access Control List)?

**ACL** stands for **Access Control List**.

ACL extends the standard Linux permission model by allowing permissions to be assigned to **specific users or groups** without changing the file owner or primary group.

Suppose you have the following directory:

```text
/project

Owner : developer
Group : devops
```

Now a tester needs temporary access to this directory.

Changing the owner is not a good idea.

Changing the group could affect other users.

Instead, you can grant permissions only to the tester using **ACL**.

This keeps the existing permissions unchanged while giving additional access to the required user.

* * *

# Why is ACL Important in DevOps?

ACL is commonly used in production environments.

Consider a web server:

```text
/var/www/html

Owner : apache
Group : apache
```

A developer needs permission to deploy files.

Changing the owner from **apache** to **developer** could break the web server.

Instead, you use **ACL** to grant the developer access while keeping Apache as the owner.

This allows:

*   Apache to continue serving the website.
    
*   Developers to deploy application files.
    
*   Existing permissions to remain unchanged.
    

This is a common practice on Linux production servers.

##### Now let's do the practical of ACls

# Understanding ACL (Access Control List)

By default, Linux permissions are controlled using three permission categories:

*   **Owner**
    
*   **Group**
    
*   **Others**
    

Sometimes these permissions are not enough.

For example, suppose you have a project directory owned by **developer**, but you want another user named **hitesh** to access it without changing the owner or the group.

Instead of modifying the ownership or group, you can use **Access Control Lists (ACLs)**.

ACL allows you to grant permissions to specific users or groups while keeping the existing ownership unchanged.

* * *

# Step 1: Create a Test File

```bash
touch project.txt
```

**Explanation**

*   `touch` → Creates an empty file named `project.txt`.
    

## If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.29.03 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/364e9d51-fbd4-48b2-bc6d-89ac2e4d030d.png align="center")

# Step 2: Check the Existing Permissions

```bash
ls -l project.txt # or type ll project.txt
```

Example Output

```text
-rw-r--r-- 1 ec2-user ec2-user 0 Aug 2 20:30 project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.29.03 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/364e9d51-fbd4-48b2-bc6d-89ac2e4d030d.png align="center")

Here,

*   Owner → `ec2-user`
    
*   Group → `ec2-user`
    
*   Others → Read only
    

At this point, **hitesh** has only the permissions available under **Others**.

* * *

# Step 3: View the Current ACL

```bash
getfacl project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.37.52 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/88a43e69-71c5-4479-83ef-e9b99b0d4270.png align="center")

**Note:** If you do not have the facl module installed in your system. Please try these commands below and then run **getfacl** to see the list.

```bash
sudo dnf install acl -y #install acl package
rpm -q acl #verify the installation
which getfacl #verify the installation
```

## What does `getfacl` do?

The **getfacl** command displays all Access Control List (ACL) entries associated with a file or directory.

It shows:

*   File owner
    
*   File group
    
*   Standard Linux permissions
    
*   Additional ACL permissions (if any)
    

Output

```text
# file: project.txt
# owner: ec2-user
# group: ec2-user
user::rw-
group::r--
other::r--
```

### Explanation

```text
| Entry | Meaning |
|--------|---------|
| user::rw- | Owner has read and write permission. |
| group::r-- | Group members have read permission. |
| other::r-- | Everyone else has read permission. |
```

Notice that there is **no ACL entry** for **hitesh**.

* * *

# Step 4: Grant Read and Write Permission to hitesh

```bash
sudo setfacl -m u:hitesh:rw project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.42.15 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/064de2f7-7414-4cb0-8477-e491b70c107d.png align="center")

## What does `setfacl` do?

The **setfacl** command is used to create, modify, or remove Access Control List (ACL) entries.

### Explanation

*   `sudo` → Executes the command with administrator privileges.
    
*   `setfacl` → Modifies the Access Control List.
    
*   `-m` → Modifies or adds a new ACL entry.
    
*   `u:` → Specifies that the ACL is for a **user**.
    
*   `hitesh` → Username receiving the permission.
    
*   `rw` → Grants Read and Write permission.
    
*   `project.txt` → File on which the ACL is being applied.
    

This command gives **hitesh** read and write permission without changing the file owner or group.

* * *

# Step 5: Verify the ACL

```bash
getfacl project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.42.15 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/064de2f7-7414-4cb0-8477-e491b70c107d.png align="center")

Example Output

```text
# file: project.txt
# owner: ec2-user
# group: ec2-user
user::rw-
user:hitesh:rw-
group::r--
mask::rw-
other::r--
```

### Explanation

| Entry | Meaning |
| --- | --- |
| user::rw- | Permissions for the file owner. |
| user:hitesh:rw- | ACL entry granting read and write permission to **hitesh**. |
| group::r-- | Permissions for the file's group. |
| mask::rw- | Maximum effective permission for named users and groups. |
| other::r-- | Permissions for everyone else. |

Notice the new line:

```text
user:hitesh:rw-
```

This indicates that **hitesh** now has **Read** and **Write** access to the file.

* * *

# Step 6: Remove the ACL Entry

```bash
sudo setfacl -x u:hitesh project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.45.49 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/d44d60ef-e305-4278-a00b-7bc1c6b1b4cc.png align="center")

### Explanation

*   `-x` → Removes an ACL entry.
    
*   `u:hitesh` → Removes the ACL assigned to the user **hitesh**.
    

* * *

# Step 7: Verify Again

```bash
getfacl project.txt
```

If you type this in the terminal you get the output as shown below.

![Screenshot 2026-08-02 at 9.45.49 PM](https://cdn.hashnode.com/uploads/covers/62db945e38759e6b49829749/d44d60ef-e305-4278-a00b-7bc1c6b1b4cc.png align="center")

The output will no longer contain:

```text
user:hitesh:rw-
```

This confirms that the ACL entry has been successfully removed.

* * *

# Key Takeaways

*   **getfacl** → Displays the Access Control List of a file or directory.
    
*   **setfacl** → Creates, modifies, or removes Access Control List entries.
    
*   ACL allows you to give permissions to specific users or groups **without changing the file owner or primary group**.
    
*   ACL is widely used in DevOps and production environments to provide temporary or additional access to deployment directories, shared projects, and application files.
    

**With this we come to the end of the tutorial 2 of Linux. Thank you for going through this. See you all in part three.. Until then Happy Learning 😀**
