Elementary Overview
On Linux, gpasswd manages local group membership, group administrators, and group-password state. The command works with /etc/group and /etc/gshadow, so it sits naturally beside groupadd, groupdel, and groupmod. A simple mental model is: those commands create, remove, or rename the group itself, while gpasswd manages who belongs to the group and who may administer it. The current gpasswd manual describes the command as an administrator for /etc/group and /etc/gshadow.
Add and Remove One User Safely
The two most useful day-to-day forms are sudo gpasswd -a alice developers and sudo gpasswd -d alice developers. The first adds alice to the supplementary group developers; the second removes her from that group. After either change, verify membership with id alice, groups alice, or getent group developers. This overlaps with usermod -aG, but gpasswd -a and -d are convenient when the task is specifically one group membership change.
Set Group Administrators and the Exact Member List
sudo gpasswd -A alice developers sets the group administrator list, while sudo gpasswd -M alice,bob,carol developers defines the group’s member list. The -M form is powerful because it sets the list rather than performing a single incremental add or delete, so it should be used carefully on a shared production group. Before changing a populated group, inspect the current state with getent group GROUP and verify it again afterward. If you only need to add or remove one person, -a or -d is usually easier to reason about.
Group Passwords Exist, but Membership Is Usually Better
Running sudo gpasswd developers can set a password for the group, and tools such as newgrp can use group-password behavior. However, the upstream manual explicitly warns that shared group passwords are an inherent security problem because multiple people may know the same secret. Modern administration normally prefers explicit user membership, individual authentication, and centralized identity controls rather than distributing one group password. sudo gpasswd -r developers removes the group password, while sudo gpasswd -R developers restricts access so only existing group members may use the group through the related group-switching mechanism. Also remember that gpasswd only edits the local /etc/group and /etc/gshadow files; LDAP or other directory-backed groups must be changed in the directory service itself.
Practical Command Set
sudo gpasswd -a alice developers— add one user to a group.sudo gpasswd -d alice developers— remove one user from a group.sudo gpasswd -A alice developers— set the group administrator list.sudo gpasswd -M alice,bob,carol developers— set the group member list.sudo gpasswd developers— interactively set a group password.sudo gpasswd -r developers— remove the group password.sudo gpasswd -R developers— restrict group access through the group-password mechanism.getent group developers— verify the current group record.id alice— inspect UID, primary GID, and supplementary groups.groups alice— quickly list the user’s groups.
Exercises
- Create a disposable lab group with
groupadd. - Add a disposable lab user with
gpasswd -a. - Verify the membership with both
idandgetent group. - Remove the same user with
gpasswd -dand verify again. - Create a second lab user and use
-Mto define an exact two-user member list. - Explain why
-Mdeserves more caution than-a. - Explain why a shared group password is usually weaker operationally than explicit user membership.
Knowledge Check + Answers
- What does
gpasswd -a USER GROUPdo? It adds the user to the named group. - What does
gpasswd -d USER GROUPdo? It removes the user from the named group. - What does
-Acontrol? The group administrator list. - What does
-Mcontrol? The group member list. - Which files does
gpasswdmanage locally?/etc/groupand/etc/gshadow. - Why are group passwords discouraged? They are shared secrets that can be known by multiple people, which weakens accountability and secret management.
- Can
gpasswddirectly change an LDAP-backed group? No. The change must be made in the corresponding directory service.
Elementary Conclusion
gpasswd fills an important gap in the Linux account-management toolkit: it manages the people inside a local group. After groupadd creates the group, groupmod changes its identity, and groupdel removes it, gpasswd handles membership and administration. The safest workflow is straightforward: inspect the group, make the smallest required membership change, then verify with getent, id, or groups. For most real systems, explicit membership is preferable to relying on a shared group password.
BitcoinVersus.Tech
Editor’s Note:
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on technical and financial subjects purely for informational purposes.

Leave a comment