The Nautilus team doesn't want its data to be accessed by any of the other groups/teams due to security reasons and want their data to be strictly accessed by the sysops group of the team.
Setup a collaborative directory /sysops/data on app server 2 in Stratos Datacenter.
The directory should be group owned by the group sysops and the group should own the files inside the directory. The directory should be read/write/execute to the user and group owners, and others should not have any access.
1. Understanding Collaborative Directories
What is a Collaborative Directory?
A collaborative directory is a shared location on a Linux system where multiple users from the same group can:
- Create files and subdirectories
- Read each other's files (with proper permissions)
- Modify or delete files (with proper permissions)
The Challenge
By default, when a user creates a file in a directory:
- The file's owner is the user who created it
- The file's group is the user's primary group (not necessarily the group of the directory)
This creates problems in collaborative environments:
- Users might not be able to edit each other's files
- Files created by different users belong to different groups
- Administrators must manually change ownership of files
The Solution: SGID
The SGID (Set Group ID) bit solves this problem by forcing all files created in a directory to inherit the directory's group ownership.
| Without SGID | With SGID |
|---|---|
| Files inherit creator's primary group | Files inherit directory's group |
| Different users create files with different groups | All files have the same group |
| Users may not access each other's files | All users in the group can collaborate |
| Manual permission management required | Automatic group inheritance |
2. The Problem: Why SGID is Needed
Scenario
The Nautilus team needs to create a shared directory /sysops/data where:
- All sysops team members can create, read, modify, and delete files
- All files created in the directory should be accessible by the entire team
- No one outside the sysops team should have access
Without SGID
# User john creates a file
[john@server]$ touch /sysops/data/file.txt
[john@server]$ ls -l /sysops/data/file.txt
-rw-r--r-- 1 john john 0 Sep 1 10:00 file.txt
# Group is 'john' (not 'sysops') - team members can't access it!
# User jane creates another file
[jane@server]$ touch /sysops/data/report.txt
[jane@server]$ ls -l /sysops/data/report.txt
-rw-r--r-- 1 jane jane 0 Sep 1 10:01 report.txt
# Group is 'jane' - different from john's file!
Problem: Team members cannot access each other's files because they belong to different groups.
With SGID
# After setting SGID on the directory
[john@server]$ touch /sysops/data/file.txt
[john@server]$ ls -l /sysops/data/file.txt
-rw-r--r-- 1 john sysops 0 Sep 1 10:00 file.txt
# Group is 'sysops' - all team members can access it!
[jane@server]$ touch /sysops/data/report.txt
[jane@server]$ ls -l /sysops/data/report.txt
-rw-r--r-- 1 jane sysops 0 Sep 1 10:01 report.txt
# Group is 'sysops' - same as john's file!
Solution: All files have the same group, enabling seamless collaboration.
3. Prerequisites
Before You Begin
- SSH access to the target server
- Root or sudo privileges
- Understanding of Linux permissions (read, write, execute)
- Basic command-line knowledge
Server Details for This Tutorial
| Detail | Value |
|---|---|
| Server | App Server 2 (stapp02) |
| User | steve |
| Password | Am3ric@ |
| Group | sysops |
| Directory | /sysops/data |
| Permissions | 770 (rwxrwx---) |
| SGID | Enabled |
4. Step-by-Step Implementation
Step 1: Connect to the Server
# Connect to the target server
ssh steve@stapp02
# Password: Am3ric@
# Switch to root
sudo su -
# Password: Am3ric@
Step 2: Create the Group
# Check if the group exists
getent group sysops
# Create the group if it doesn't exist
groupadd sysops
# Verify the group was created
getent group sysops
Output:
sysops:x:1001:
Step 3: Create the Directory
# Create the directory with parent directories if needed
mkdir -p /sysops/data
# Verify the directory was created
ls -ld /sysops/data
Output:
drwxr-xr-x 2 root root 4096 Sep 1 10:00 /sysops/data
Step 4: Set Group Ownership
# Change the group ownership recursively
chgrp -R sysops /sysops/data
# Verify the group ownership
ls -ld /sysops/data
Output:
drwxr-xr-x 2 root sysops 4096 Sep 1 10:00 /sysops/data
Step 5: Set Permissions (770)
# Set permissions: rwx for owner, rwx for group, nothing for others
chmod 770 /sysops/data
# Verify permissions
ls -ld /sysops/data
Output:
drwxrwx--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
Step 6: Enable SGID
# Set the SGID bit
chmod g+s /sysops/data
# Verify SGID is set (look for 's' in group permissions)
ls -ld /sysops/data
Output:
drwxrws--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
# ^
# 's' indicates SGID is set
Step 7: Add Users to the Group
# Add users to the sysops group
usermod -aG sysops username
# Verify users are in the group
groups username
# Example: Add multiple users
usermod -aG sysops john
usermod -aG sysops jane
usermod -aG sysops bob
5. Understanding the Permissions
The Final Permission: drwxrws---
d rwx rws ---
│ │ │ │
│ │ │ └── Others: No permissions
│ │ └──────── Group: read, write, execute + SGID
│ └───────────── Owner: read, write, execute
└───────────────── File type: Directory
Permission Breakdown
| Component | Permission | Octal | Meaning |
|---|---|---|---|
| Owner (root) | rwx |
7 | Full control |
| Group (sysops) | rws |
7 | Full control + SGID |
| Others | --- |
0 | No access |
| Full Octal | 2770 |
- | 2 (SGID) + 770 |
What Each Permission Means
| Permission | Files | Directories |
|---|---|---|
| Read (r) | View file contents | List directory contents |
| Write (w) | Modify file contents | Create/delete files |
| Execute (x) | Execute file | Enter directory |
| SGID (s) | Not applicable | Files inherit group |
SGID vs SUID vs Sticky Bit
| Bit | Symbol | Files | Directories |
|---|---|---|---|
| SUID |
s in user permissions |
Execute with owner's privileges | Not applicable |
| SGID |
s in group permissions |
Execute with group's privileges | Files inherit group |
| Sticky |
t in others permissions |
Not applicable | Only owner can delete |
6. Testing and Verification
Test 1: Verify SGID Inheritance
# Create a test file
touch /sysops/data/testfile
# Check the file's group
ls -la /sysops/data/testfile
Expected Output:
-rw-r--r-- 1 root sysops 0 Sep 1 10:00 /sysops/data/testfile
# ^^^^^
# Group is 'sysops'
Test 2: Test as Another User
# Switch to a user in the sysops group
su - john
# Navigate to the directory
cd /sysops/data
# Create a file
touch johns_file.txt
# Check the file's group
ls -la johns_file.txt
Expected Output:
-rw-r--r-- 1 john sysops 0 Sep 1 10:01 johns_file.txt
# ^^^^^
# Group is 'sysops'
Test 3: Verify Others Have No Access
# Try to access as a user not in the group
sudo -u nobody ls /sysops/data
Expected Output:
ls: cannot open directory /sysops/data: Permission denied
Comprehensive Verification Script
#!/bin/bash
echo "========================================="
echo "Verifying Collaborative Directory"
echo "========================================="
echo ""
echo "=== 1. Directory Permissions ==="
ls -ld /sysops/data
echo ""
echo "=== 2. Group Ownership ==="
stat -c "%G" /sysops/data
echo ""
echo "=== 3. Octal Permissions ==="
stat -c "%a" /sysops/data
echo ""
echo "=== 4. SGID Bit Check ==="
if [ -g /sysops/data ]; then
echo "✓ SGID bit is set"
else
echo "✗ SGID bit is NOT set"
fi
echo ""
echo "=== 5. File Inheritance Test ==="
touch /sysops/data/inheritance_test
ls -la /sysops/data/inheritance_test
rm -f /sysops/data/inheritance_test
echo ""
echo "=== 6. Group Members ==="
getent group sysops | cut -d: -f4
echo ""
echo "========================================="
echo "✅ Verification Complete!"
echo "========================================="
7. Troubleshooting Common Issues
Issue 1: "Group 'sysops' does not exist"
Problem: The group hasn't been created yet.
Solution:
# Create the group
groupadd sysops
# Verify creation
getent group sysops
Issue 2: "mkdir: cannot create directory: Permission denied"
Problem: Insufficient privileges.
Solution:
# Use sudo or become root
sudo mkdir -p /sysops/data
Issue 3: Files are not inheriting the group
Problem: SGID bit is not set or was removed.
Solution:
# Check if SGID is set
ls -ld /sysops/data
# If not set, add it
chmod g+s /sysops/data
# Verify it's set
ls -ld /sysops/data | grep -q "s" && echo "✓ SGID set"
Issue 4: "Permission denied" when accessing directory
Problem: User is not a member of the sysops group.
Solution:
# Add user to group
usermod -aG sysops username
# Verify user is in group
groups username
# User must log out and back in for changes to take effect
Issue 5: "chgrp: invalid group: sysops"
Problem: The group name is misspelled or doesn't exist.
Solution:
# Check if group exists
getent group sysops
# If not, create it
groupadd sysops
# Try the chgrp command again
chgrp -R sysops /sysops/data
Issue 6: Existing files don't inherit group
Problem: Only new files inherit the group via SGID.
Solution: Fix existing files manually:
# Change group of existing files
chgrp -R sysops /sysops/data
# Set SGID for future files
chmod g+s /sysops/data
Issue 7: "Operation not permitted" when setting SGID
Problem: Insufficient privileges or filesystem doesn't support SGID.
Solution:
# Use sudo
sudo chmod g+s /sysops/data
# Check filesystem support
df -T /sysops/data
8. Best Practices
1. Use Meaningful Group Names
# Good
groupadd sysops
groupadd developers
groupadd finance
# Not recommended
groupadd team1
groupadd groupA
2. Document the Setup
# Create a README file in the directory
cat > /sysops/data/README.txt << EOF
Collaborative Directory for Sysops Team
======================================
Purpose: Shared workspace for sysops team members
Created: $(date)
Manager: $(whoami)
Group: sysops
Permissions: drwxrws--- (2770)
SGID: Enabled
Users with access:
$(getent group sysops | cut -d: -f4)
EOF
3. Set Default Permissions with umask
# For users in the group, set umask to ensure files are group-readable
umask 002
4. Create a Login Script
# Add to /etc/profile or user's .bashrc
if [ -d /sysops/data ]; then
umask 002
echo "Welcome to the Sysops collaborative workspace"
echo "Location: /sysops/data"
fi
5. Regular Audits
# Check directory permissions periodically
ls -ld /sysops/data
# Check for unauthorized access
auditctl -w /sysops/data -p rwxa -k sysops_data
6. Backup Configuration
# Document the configuration
cat > /root/sysops_dir_config.txt << EOF
Directory: /sysops/data
Group: sysops
Permissions: 2770
Created: $(date)
SGID: Enabled
Users: $(getent group sysops | cut -d: -f4)
EOF
9. Advanced Configurations
1. Creating Multiple Collaborative Directories
#!/bin/bash
# Create multiple collaborative directories
GROUPS=("sysops" "developers" "finance" "hr")
BASE_DIR="/shared"
for group in "${GROUPS[@]}"; do
# Create group if it doesn't exist
groupadd "$group" 2>/dev/null
# Create directory
mkdir -p "$BASE_DIR/$group"
# Set permissions
chgrp -R "$group" "$BASE_DIR/$group"
chmod 2770 "$BASE_DIR/$group"
echo "Created: $BASE_DIR/$group (Group: $group)"
done
2. Setting Default ACLs
For more granular control, use ACLs (Access Control Lists):
# Set default ACLs for the directory
setfacl -d -m g:sysops:rwx /sysops/data
setfacl -d -m u::rwx /sysops/data
setfacl -d -m g::rwx /sysops/data
# Verify ACLs
getfacl /sysops/data
3. Mounting with SGID Support
For NFS-mounted directories, ensure SGID is supported:
# /etc/fstab entry with proper options
server:/exports/data /sysops/data nfs defaults,noatime 0 0
# Mount with specific options
mount -o defaults,sgid /dev/sdb1 /sysops/data
4. Automated User Onboarding
#!/bin/bash
# Add users to the sysops group automatically
add_user_to_sysops() {
local username=$1
# Check if user exists
if id "$username" &>/dev/null; then
usermod -aG sysops "$username"
echo "✓ $username added to sysops group"
else
echo "✗ $username does not exist"
return 1
fi
}
# Usage
add_user_to_sysops "john"
add_user_to_sysops "jane"
add_user_to_sysops "bob"
10. Conclusion
What We've Accomplished
| Task | Command | Status |
|---|---|---|
| Create group | groupadd sysops |
✅ |
| Create directory | mkdir -p /sysops/data |
✅ |
| Set group ownership | chgrp -R sysops /sysops/data |
✅ |
| Set permissions | chmod 770 /sysops/data |
✅ |
| Enable SGID | chmod g+s /sysops/data |
✅ |
| Add users to group | usermod -aG sysops user |
✅ |
| Test SGID inheritance | touch /sysops/data/test |
✅ |
Key Takeaways
- SGID is essential for collaborative directories
- Permissions 770 ensures group-only access
- Files inherit group automatically with SGID
- Users must be in the group to access files
- Testing is critical to verify configuration
The Complete Solution
# Complete one-liner
groupadd sysops && mkdir -p /sysops/data && chgrp -R sysops /sysops/data && chmod 770 /sysops/data && chmod g+s /sysops/data
# Verification
ls -ld /sysops/data
# Output: drwxrws--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
Benefits of This Configuration
| Benefit | Description |
|---|---|
| Automatic Group Inheritance | All files belong to sysops group |
| Simplified Collaboration | Team members can access all files |
| Security | Only group members have access |
| Reduced Admin Work | No manual permission changes needed |
| Consistency | All files follow the same permission model |
Related Topics
- ACLs (Access Control Lists): For more granular permissions
- Sticky Bit: For preventing file deletion by non-owners
- SUID: For executing files with the owner's privileges
- Umask: For setting default file permissions
Automation Tools
| Tool | Purpose |
|---|---|
| Ansible | Infrastructure as code |
| Puppet | Configuration management |
| Chef | Automation platform |
| SaltStack | Remote execution |
Appendix: Quick Reference
Commands Quick Reference
| Command | Purpose |
|---|---|
getent group sysops |
Check if group exists |
groupadd sysops |
Create group |
mkdir -p /sysops/data |
Create directory |
chgrp -R sysops /sysops/data |
Set group ownership |
chmod 770 /sysops/data |
Set permissions |
chmod g+s /sysops/data |
Set SGID |
ls -ld /sysops/data |
View permissions |
usermod -aG sysops user |
Add user to group |
Permission Quick Reference
| Octal | Symbolic | Description |
|---|---|---|
700 |
rwx------ |
Owner only |
770 |
rwxrwx--- |
Owner + Group |
2770 |
rwxrws--- |
Owner + Group + SGID |
750 |
rwxr-x--- |
Owner (full), Group (read/execute) |
755 |
rwxr-xr-x |
Owner (full), Group (read/execute), Others (read/execute) |
Top comments (0)