CompTIA Linux+ (XK0-006)Services and User ManagementMedium
A system administrator is auditing the `/etc/passwd` file and notices an entry for a user `legacyuser` with `::/bin/false` as the shell. What does this configuration indicate regarding `legacyuser`'s login capabilities?
- AThe user can only log in via SSH with key-based authentication.
- BThe user can log in, but will immediately be logged out without a shell.
- CThe user's account is locked, preventing any login.
- DThe user can only execute commands with `sudo`.
Show answer & explanationAnswer & explanation
Correct answer: B. The user can log in, but will immediately be logged out without a shell.
When `/bin/false` or `/sbin/nologin` is set as a user's login shell, it means the user cannot initiate an interactive login session. Upon successful authentication, the system attempts to execute `/bin/false` (or `/sbin/nologin`), which immediately exits, thus logging the user out.
Why the other options are wrong
- A. This shell prevents any interactive login, regardless of authentication method.
- C. The account isn't locked; authentication is possible, but a shell isn't provided.
- D. The ability to use `sudo` depends on `/etc/sudoers` configuration, not the login shell.
Non-Login Shells
Using `/bin/false` or `/sbin/nologin` as a user's shell prevents interactive login sessions by immediately exiting upon login.
- User can authenticate but gets no shell.
- Common for service accounts or disabled user accounts.
- Different from locking an account (e.g., `passwd -l`).
Memory trick: Shell's a 'door', `false` means 'no entry'.