The Account Files

Where Accounts Live

Linux is a multi-user system at its core, even on a laptop only you ever touch. Every account - yours, the system's, a service's - is a row in a plain text file, not some hidden database.

FileHoldsNotable
/etc/passwdUser accountsWorld-readable, no passwords
/etc/shadowPassword hashes + ageingRoot-only
/etc/groupGroup definitionsGroup membership
/etc/gshadowGroup passwords/adminsRoot-only

The name /etc/passwd is historical and misleading today - it used to actually store passwords decades ago, before that was recognized as a security problem (the file has to be world-readable so every program can look up usernames). Passwords were moved out into /etc/shadow, which only root can read, leaving /etc/passwd holding just account metadata.

A /etc/passwd line has 7 colon-separated fields:

alice:x:1001:1001:Alice Smith:/home/alice:/bin/bash
  |   |   |    |       |          |          └ login shell
  |   |   |    |       |          └ home directory
  |   |   |    |       └ GECOS (comment)
  |   |   |    └ primary GID
  |   |   └ UID
  |   └ password placeholder (x = see /etc/shadow)
  └ username

That x in the second field is the tell: it's not a password, it's a placeholder meaning "the real hash lives in /etc/shadow, go look there (and you'll need root)."

Tip: The kernel doesn't actually know or care about usernames - internally, every process and file is owned by a numeric UID (User ID). alice is just a human-friendly label that tools translate to and from UID 1001 by reading /etc/passwd. UID 0 is always root, no matter what it's named. System accounts (used by background services, not people) are typically UID < 1000; regular human users start at 1000 on Debian/RHEL - the exact cutoff is configurable in /etc/login.defs.