getent
Query the name service the rest of the system uses
getent asks the Name Service Switch for an entry and prints it in the format of the file that
database is modelled on. On a default Debian install the file is the only source, so
getent passwd tips-ops prints the same line as grep '^tips-ops:' /etc/passwd. Once accounts
also come from LDAP, Active Directory or systemd-homed, the file holds only the local ones:
getent still finds the rest, and the grep finds nothing, without an error to say why.
Which sources are consulted, and in what order, is governed by /etc/nsswitch.conf. getent reads
it the way every other program on the system does, so a script that uses it sees the accounts a
login or a service would see. One that greps the file works on the machine it was written on and
finds nothing on a machine whose accounts live somewhere else.
The databases go well beyond accounts. hosts, services and protocols are the other three
worth knowing, and each saves opening a file under /etc and reading it by eye.
Sample files used on this page
Every example below was run against these files. Recreate them to follow along.
the accounts, and a host that exists only in /etc/hosts The same accounts as id, and the first two are the ones managing-users starts from, so the three pages name the same people. tips-ops holds tips-deploy as a supplementary group and tips-site holds it as its primary one, which is the difference the group listing below does not show. backup.example.com is in /etc/hosts and no DNS server has a record for it: example.com is reserved by RFC 2606 and 192.0.2.0/24 by RFC 5737, so the name cannot collide with a real host and the address cannot route to one.
tips-dev:x:1001:1001:Deployment account:/home/tips-dev:/bin/bash
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash
tips-site:x:1010:4000:Website account:/home/tips-site:/bin/bash
tips-deploy:x:4000:tips-ops
192.0.2.10 backup.example.com backup
Looking up an account or a group
The passwd and group databases print a record in the format of the file they are named after, colons and all. The key may be the name or the number.
Read one account's record
getent passwd tips-ops
Name, password placeholder, uid, primary gid, description, home directory, shell. The x is not a password: it means the hash lives in /etc/shadow, which is a separate database with separate permissions.
Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash
Look an account up by its number
getent passwd 1002
Numeric keys work on every database that has them, so this puts a name to a uid in output that carries bare numbers. id -un does the same lookup and prints only the name.
Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash
Read a group's membership
getent group tips-deploy
The fourth field is the member list. Membership is recorded here, on the group, and an account's own record has no field naming its supplementary groups, so finding every group one account is in means walking every group. id -G does that walk for you.
Show output
tips-deploy:x:4000:tips-ops
Look up a key that doesn't exist
getent passwd nosuchuser; echo "exit $?"
Nothing on standard output and status 2, which is the number to test for: it is what separates a key that is not there from a misspelled database, which the next example shows exiting 1.
Show output
exit 2
Look up a database that doesn't exist
getent nosuchdb tips-ops 2>&1; echo "exit $?"
Status 1 rather than 2, so the two failures are distinguishable. It is the typo case: the database is group, and getent groups stops here with this message.
Show output
Unknown database: nosuchdb
Try `getent --help' or `getent --usage' for more information.
exit 1
Where a result comes from, and who may read it
getent is a thin wrapper over the same library calls every other program makes, so it consults the sources named in /etc/nsswitch.conf in the order written there.
See where each database looks things up
grep -E "^(passwd|group|hosts):" /etc/nsswitch.conf
A stock Debian install answers accounts from files alone, and hostnames from the file first and DNS after. Joining a machine to LDAP or Active Directory adds a source to these lines, and, from then on, a grep of /etc/passwd only sees a fraction of the accounts.
Show output
passwd: files
group: files
hosts: files dns
Force one source and skip the rest
getent -s files passwd tips-ops
-s overrides nsswitch.conf for this call only. Requesting files explicitly is how to find out whether an account is local or comes from the directory, without editing anything or restarting a service.
Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash
Prove the file was skipped
getent -s dns hosts backup.example.com; echo "exit $?"
The name is only in /etc/hosts, as the fixture above shows, and no DNS server has a record for it, so a lookup restricted to DNS finds nothing. /etc/hosts was never read.
Show output
exit 2
Read the shadow database as root and as anybody else
getent shadow tips-dev | cut -d: -f1,2; runuser -u user -- getent shadow tips-dev; echo "exit $?"
Trimmed to the first two fields because the rest are day counts that move. ! is a locked password. The second call makes the same lookup as an ordinary account and gets status 2, the same result as for a name that does not exist. /etc/shadow is mode 640, owned by root and group shadow, so the lookup cannot open the file and reports finding nothing rather than being refused.
Show output
tips-dev:!
exit 2
Members a group listing leaves out
A group's fourth field names the accounts that hold it as a supplementary group. An account whose primary group it is has the membership recorded on its own record instead, and appears in neither field the other one prints.
Find the member the group does not mention
getent passwd tips-site; id -Gn tips-site
The fourth field of the account record is 4000, which is tips-deploy, and getent group tips-deploy above lists only tips-ops. Auditing a group by reading its member list therefore misses everyone who was added with adduser --ingroup, and id is the command that does not.
Show output
tips-site:x:1010:4000:Website account:/home/tips-site:/bin/bash
tips-deploy users
The databases that are not about accounts
Anything with a file under /etc and a lookup function in the C library is reachable here, which saves guessing at a format or remembering a path.
Resolve a hostname the way the system does
getent hosts backup.example.com
Address first, then every name the entry carries. This follows nsswitch.conf, so it sees /etc/hosts and returns what a program connecting to the name would get, which a tool that queries DNS directly cannot. getent ahosts asks through getaddrinfo instead and reports every address family and socket type separately.
Show output
192.0.2.10 backup.example.com backup
Put a number to a service name, or the reverse
getent services ssh; getent services 80/tcp
Either direction, from /etc/services. Handy when reading firewall rules or ss output that has been left numeric, and quicker than searching a file of three hundred-odd entries by eye.
Show output
ssh 22/tcp
http 80/tcp www
Put a number to a protocol
getent protocols tcp
The number an IP header carries to say what follows it, and the table iptables -p tcp consults to turn the name into it. 6 for TCP, 17 for UDP, 1 for ICMP.
Show output
tcp 6 TCP