The Account Files
Where Accounts Live
Linux is a multi-user system at its core, even on a laptop only you ever touch. Every account - yours, the system's, a service's - is a row in a plain text file, not some hidden database.
| File | Holds | Notable |
|---|---|---|
/etc/passwd | User accounts | World-readable, no passwords |
/etc/shadow | Password hashes + ageing | Root-only |
/etc/group | Group definitions | Group membership |
/etc/gshadow | Group passwords/admins | Root-only |
The name /etc/passwd is historical and misleading today - it used to actually store passwords decades ago, before that was recognized as a security problem (the file has to be world-readable so every program can look up usernames). Passwords were moved out into /etc/shadow, which only root can read, leaving /etc/passwd holding just account metadata.
A /etc/passwd line has 7 colon-separated fields:
alice:x:1001:1001:Alice Smith:/home/alice:/bin/bash
| | | | | | └ login shell
| | | | | └ home directory
| | | | └ GECOS (comment)
| | | └ primary GID
| | └ UID
| └ password placeholder (x = see /etc/shadow)
└ username
That x in the second field is the tell: it's not a password, it's a placeholder meaning "the real hash lives in /etc/shadow, go look there (and you'll need root)."
Tip: The kernel doesn't actually know or care about usernames - internally, every process and file is owned by a numeric UID (User ID).aliceis just a human-friendly label that tools translate to and from UID 1001 by reading/etc/passwd. UID 0 is always root, no matter what it's named. System accounts (used by background services, not people) are typically UID < 1000; regular human users start at 1000 on Debian/RHEL - the exact cutoff is configurable in/etc/login.defs.