⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Junior / Associate DevOps [L1] Linux Allow user 'deploy' to restart nginx and read syslog only Core Fundamentals [L1]

Q: What does the `/etc/shadow` file contain, and why is it separated from `/etc/passwd`?

/etc/passwd contains user account information (username, UID, GID, home directory, shell) and historically stored password hashes. Howeve...

#Linux #Allow user 'deploy' to restart nginx and read syslog only #L1 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""We encountered this OS-level bottleneck during peak traffic and diagnosed it down to kernel and filesystem metrics. The interviewer is testing: Linux authentication files, password security.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

/etc/passwd contains user account information (username, UID, GID, home directory, shell) and historically stored password hashes. However, /etc/passwd must be world-readable because many programs need to map UIDs to usernames.

  • Username
  • Hashed password (using algorithms like SHA-512, prefixed with $6$)
  • Date of last password change (in days since epoch)
  • Minimum days between password changes
2️⃣

Remediation & Permanent Safeguards

/etc/shadow was introduced to separate the sensitive password hashes into a file that is readable only by root (permissions 640 or 600). This prevents unprivileged users from reading hashed passwords and attempting offline brute-force attacks. Each line in /etc/shadow contains: To check password aging for a user: chage -l username. To force a password change on next login: chage -d 0 username.

  • Maximum password age
  • Warning period before expiry
  • Account expiration date
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Username."
⚡ 60-Second Elevator Pitch Talking Points
  • Username
  • Hashed password (using algorithms like SHA-512, prefixed with $6$)
  • Date of last password change (in days since epoch)
Advertisement
Want more Linux scenarios?
Explore our complete collection of scenario-based Linux interview runbooks.
Browse All Linux Questions →

📚 Related Production Scenarios in Linux