Where Linux keeps its users
Linux is the system that runs most servers. It stores its accounts in a plain text file named /etc/passwd. Each line is one user. A line has several parts split by a colon, like this:
john:x:1001:1001:John Smith:/home/john:/bin/bash
From left to right, the parts are: user name, a password marker, user ID number, group ID number, a comment, the home folder, and the login shell (the program that starts when the user logs in).
Steps
- Open a terminal on your server, or connect with SSH.
- List every user:
cat /etc/passwd
This prints the whole file.
- Show only the user names:
cut -d: -f1 /etc/passwd
The cut command splits each line at the colon and keeps part one.
- Sort the names in A to Z order:
cut -d: -f1 /etc/passwd | sort
The bar sends the result of one command into the next.
- Count the users:
cut -d: -f1 /etc/passwd | wc -l
The wc -l part counts lines.
Filter the list
- Find one user by name:
This shows only the line that starts with john.grep '^john:' /etc/passwd - Show only real people (user ID 1000 or higher on most systems):
This prints the name when the third part is 1000 or more.awk -F: '$3 >= 1000 {print $1}' /etc/passwd - Show users who can log in with a shell:
This hides accounts that are blocked from logging in.grep -v -E 'nologin|false' /etc/passwd | cut -d: -f1
Other helpful commands
whoshows who is logged in right now.lastshows recent logins.getent passwdlists users, including ones from other sources.id johnshows the ID and groups of one user.
Tip: Many users in the list are system accounts used by programs. That is normal. Do not delete them.
Quick recap
- Users are stored in
/etc/passwd. - Use
cut -d: -f1to see only names. - Use
grepto find one user. - Use
awkto show users with ID 1000 or higher. - Use
whoandlastto see logins.