The Nautilus team doesn’t want its data to be accessed by any of the other groups/teams due to security reasons and want their data to be strictly accessed by the sysops group of the team.
Setup a collaborative directory /sysops/data on app server 2 in Stratos Datacenter.
The directory should be group owned by the group sysops and the group should own the files inside the directory. The directory should be read/write/execute to the user and group owners, and others should not have any access.
1. Understanding Collaborative Directories
What is a Collaborative Directory?
A collaborative directory is a shared location on a Linux system where multiple users from the same group can:
- Create files and subdirectories
- Read each other’s files (with proper permissions)
- Modify or delete files (with proper permissions)
The Challenge
By default, when a user creates a file in a directory:
- The file’s owner is the user who created it
- The file’s group is the user’s primary group (not necessarily the group of the directory)
This creates problems in collaborative environments:
- Users might not be able to edit each other’s files
- Files created by different users belong to different groups
- Administrators must manually change ownership of files
The Solution: SGID
The SGID (Set Group ID) bit solves this problem by forcing all files created in a directory to inherit the directory’s group ownership.
Without SGID With SGID Files inherit creator’s primary group Files inherit directory’s group Different users create files with different groups All files have the same group Users may not access each other’s files All users in the group can collaborate Manual permission management required Automatic group inheritance2. The Problem: Why SGID is Needed
Scenario
The Nautilus team needs to create a shared directory /sysops/data where:
- All sysops team members can create, read, modify, and delete files
- All files created in the directory should be accessible by the entire team
- No one outside the sysops team should have access
Without SGID
# User john creates a file
[john@server]$ touch /sysops/data/file.txt
[john@server]$ ls -l /sysops/data/file.txt
-rw-r--r-- 1 john john 0 Sep 1 10:00 file.txt
# Group is 'john' (not 'sysops') - team members can't access it!
# User jane creates another file
[jane@server]$ touch /sysops/data/report.txt
[jane@server]$ ls -l /sysops/data/report.txt
-rw-r--r-- 1 jane jane 0 Sep 1 10:01 report.txt
# Group is 'jane' - different from john's file!
Enter fullscreen mode Exit fullscreen mode
Problem: Team members cannot access each other’s files because they belong to different groups.
With SGID
# After setting SGID on the directory
[john@server]$ touch /sysops/data/file.txt
[john@server]$ ls -l /sysops/data/file.txt
-rw-r--r-- 1 john sysops 0 Sep 1 10:00 file.txt
# Group is 'sysops' - all team members can access it!
[jane@server]$ touch /sysops/data/report.txt
[jane@server]$ ls -l /sysops/data/report.txt
-rw-r--r-- 1 jane sysops 0 Sep 1 10:01 report.txt
# Group is 'sysops' - same as john's file!
Enter fullscreen mode Exit fullscreen mode
Solution: All files have the same group, enabling seamless collaboration.
3. Prerequisites
Before You Begin
- SSH access to the target server
- Root or sudo privileges
- Understanding of Linux permissions (read, write, execute)
- Basic command-line knowledge
Server Details for This Tutorial
Detail Value Server App Server 2 (stapp02) User steve Password Am3ric@ Group sysops Directory /sysops/data Permissions 770 (rwxrwx—) SGID Enabled4. Step-by-Step Implementation
Step 1: Connect to the Server
# Connect to the target server
ssh steve@stapp02
# Password: Am3ric@
# Switch to root
sudo su -
# Password: Am3ric@
Enter fullscreen mode Exit fullscreen mode
Step 2: Create the Group
# Check if the group exists
getent group sysops
# Create the group if it doesn't exist
groupadd sysops
# Verify the group was created
getent group sysops
Enter fullscreen mode Exit fullscreen mode
Output:
sysops:x:1001:
Enter fullscreen mode Exit fullscreen mode
Step 3: Create the Directory
# Create the directory with parent directories if needed
mkdir -p /sysops/data
# Verify the directory was created
ls -ld /sysops/data
Enter fullscreen mode Exit fullscreen mode
Output:
drwxr-xr-x 2 root root 4096 Sep 1 10:00 /sysops/data
Enter fullscreen mode Exit fullscreen mode
Step 4: Set Group Ownership
# Change the group ownership recursively
chgrp -R sysops /sysops/data
# Verify the group ownership
ls -ld /sysops/data
Enter fullscreen mode Exit fullscreen mode
Output:
drwxr-xr-x 2 root sysops 4096 Sep 1 10:00 /sysops/data
Enter fullscreen mode Exit fullscreen mode
Step 5: Set Permissions (770)
# Set permissions: rwx for owner, rwx for group, nothing for others
chmod 770 /sysops/data
# Verify permissions
ls -ld /sysops/data
Enter fullscreen mode Exit fullscreen mode
Output:
drwxrwx--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
Enter fullscreen mode Exit fullscreen mode
Step 6: Enable SGID
# Set the SGID bit
chmod g+s /sysops/data
# Verify SGID is set (look for 's' in group permissions)
ls -ld /sysops/data
Enter fullscreen mode Exit fullscreen mode
Output:
drwxrws--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
# ^
# 's' indicates SGID is set
Enter fullscreen mode Exit fullscreen mode
Step 7: Add Users to the Group
# Add users to the sysops group
usermod -aG sysops username
# Verify users are in the group
groups username
# Example: Add multiple users
usermod -aG sysops john
usermod -aG sysops jane
usermod -aG sysops bob
Enter fullscreen mode Exit fullscreen mode
5. Understanding the Permissions
The Final Permission: drwxrws---
d rwx rws ---
│ │ │ │
│ │ │ └── Others: No permissions
│ │ └──────── Group: read, write, execute + SGID
│ └───────────── Owner: read, write, execute
└───────────────── File type: Directory
Enter fullscreen mode Exit fullscreen mode
Permission Breakdown
Component Permission Octal Meaning Owner (root)rwx
7
Full control
Group (sysops)
rws
7
Full control + SGID
Others
---
0
No access
Full Octal
2770
–
2 (SGID) + 770
What Each Permission Means
Permission Files Directories Read (r) View file contents List directory contents Write (w) Modify file contents Create/delete files Execute (x) Execute file Enter directory SGID (s) Not applicable Files inherit groupSGID vs SUID vs Sticky Bit
Bit Symbol Files Directories SUIDs in user permissions
Execute with owner’s privileges
Not applicable
SGID
s in group permissions
Execute with group’s privileges
Files inherit group
Sticky
t in others permissions
Not applicable
Only owner can delete
6. Testing and Verification
Test 1: Verify SGID Inheritance
# Create a test file
touch /sysops/data/testfile
# Check the file's group
ls -la /sysops/data/testfile
Enter fullscreen mode Exit fullscreen mode
Expected Output:
-rw-r--r-- 1 root sysops 0 Sep 1 10:00 /sysops/data/testfile
# ^^^^^
# Group is 'sysops'
Enter fullscreen mode Exit fullscreen mode
Test 2: Test as Another User
# Switch to a user in the sysops group
su - john
# Navigate to the directory
cd /sysops/data
# Create a file
touch johns_file.txt
# Check the file's group
ls -la johns_file.txt
Enter fullscreen mode Exit fullscreen mode
Expected Output:
-rw-r--r-- 1 john sysops 0 Sep 1 10:01 johns_file.txt
# ^^^^^
# Group is 'sysops'
Enter fullscreen mode Exit fullscreen mode
Test 3: Verify Others Have No Access
# Try to access as a user not in the group
sudo -u nobody ls /sysops/data
Enter fullscreen mode Exit fullscreen mode
Expected Output:
ls: cannot open directory /sysops/data: Permission denied
Enter fullscreen mode Exit fullscreen mode
Comprehensive Verification Script
#!/bin/bash
echo "========================================="
echo "Verifying Collaborative Directory"
echo "========================================="
echo ""
echo "=== 1. Directory Permissions ==="
ls -ld /sysops/data
echo ""
echo "=== 2. Group Ownership ==="
stat -c "%G" /sysops/data
echo ""
echo "=== 3. Octal Permissions ==="
stat -c "%a" /sysops/data
echo ""
echo "=== 4. SGID Bit Check ==="
if [ -g /sysops/data ]; then
echo "✓ SGID bit is set"
else
echo "✗ SGID bit is NOT set"
fi
echo ""
echo "=== 5. File Inheritance Test ==="
touch /sysops/data/inheritance_test
ls -la /sysops/data/inheritance_test
rm -f /sysops/data/inheritance_test
echo ""
echo "=== 6. Group Members ==="
getent group sysops | cut -d: -f4
echo ""
echo "========================================="
echo "✅ Verification Complete!"
echo "========================================="
Enter fullscreen mode Exit fullscreen mode
7. Troubleshooting Common Issues
Issue 1: “Group ‘sysops’ does not exist”
Problem: The group hasn’t been created yet.
Solution:
# Create the group
groupadd sysops
# Verify creation
getent group sysops
Enter fullscreen mode Exit fullscreen mode
Issue 2: “mkdir: cannot create directory: Permission denied”
Problem: Insufficient privileges.
Solution:
# Use sudo or become root
sudo mkdir -p /sysops/data
Enter fullscreen mode Exit fullscreen mode
Issue 3: Files are not inheriting the group
Problem: SGID bit is not set or was removed.
Solution:
# Check if SGID is set
ls -ld /sysops/data
# If not set, add it
chmod g+s /sysops/data
# Verify it's set
ls -ld /sysops/data | grep -q "s" && echo "✓ SGID set"
Enter fullscreen mode Exit fullscreen mode
Issue 4: “Permission denied” when accessing directory
Problem: User is not a member of the sysops group.
Solution:
# Add user to group
usermod -aG sysops username
# Verify user is in group
groups username
# User must log out and back in for changes to take effect
Enter fullscreen mode Exit fullscreen mode
Issue 5: “chgrp: invalid group: sysops”
Problem: The group name is misspelled or doesn’t exist.
Solution:
# Check if group exists
getent group sysops
# If not, create it
groupadd sysops
# Try the chgrp command again
chgrp -R sysops /sysops/data
Enter fullscreen mode Exit fullscreen mode
Issue 6: Existing files don’t inherit group
Problem: Only new files inherit the group via SGID.
Solution: Fix existing files manually:
# Change group of existing files
chgrp -R sysops /sysops/data
# Set SGID for future files
chmod g+s /sysops/data
Enter fullscreen mode Exit fullscreen mode
Issue 7: “Operation not permitted” when setting SGID
Problem: Insufficient privileges or filesystem doesn’t support SGID.
Solution:
# Use sudo
sudo chmod g+s /sysops/data
# Check filesystem support
df -T /sysops/data
Enter fullscreen mode Exit fullscreen mode
8. Best Practices
1. Use Meaningful Group Names
# Good
groupadd sysops
groupadd developers
groupadd finance
# Not recommended
groupadd team1
groupadd groupA
Enter fullscreen mode Exit fullscreen mode
2. Document the Setup
# Create a README file in the directory
cat > /sysops/data/README.txt << EOF
Collaborative Directory for Sysops Team
======================================
Purpose: Shared workspace for sysops team members
Created: $(date)
Manager: $(whoami)
Group: sysops
Permissions: drwxrws--- (2770)
SGID: Enabled
Users with access:
$(getent group sysops | cut -d: -f4)
EOF
Enter fullscreen mode Exit fullscreen mode
3. Set Default Permissions with umask
# For users in the group, set umask to ensure files are group-readable
umask 002
Enter fullscreen mode Exit fullscreen mode
4. Create a Login Script
# Add to /etc/profile or user's .bashrc
if [ -d /sysops/data ]; then
umask 002
echo "Welcome to the Sysops collaborative workspace"
echo "Location: /sysops/data"
fi
Enter fullscreen mode Exit fullscreen mode
5. Regular Audits
# Check directory permissions periodically
ls -ld /sysops/data
# Check for unauthorized access
auditctl -w /sysops/data -p rwxa -k sysops_data
Enter fullscreen mode Exit fullscreen mode
6. Backup Configuration
# Document the configuration
cat > /root/sysops_dir_config.txt << EOF
Directory: /sysops/data
Group: sysops
Permissions: 2770
Created: $(date)
SGID: Enabled
Users: $(getent group sysops | cut -d: -f4)
EOF
Enter fullscreen mode Exit fullscreen mode
9. Advanced Configurations
1. Creating Multiple Collaborative Directories
#!/bin/bash
# Create multiple collaborative directories
GROUPS=("sysops" "developers" "finance" "hr")
BASE_DIR="/shared"
for group in "${GROUPS[@]}"; do
# Create group if it doesn't exist
groupadd "$group" 2>/dev/null
# Create directory
mkdir -p "$BASE_DIR/$group"
# Set permissions
chgrp -R "$group" "$BASE_DIR/$group"
chmod 2770 "$BASE_DIR/$group"
echo "Created: $BASE_DIR/$group (Group: $group)"
done
Enter fullscreen mode Exit fullscreen mode
2. Setting Default ACLs
For more granular control, use ACLs (Access Control Lists):
# Set default ACLs for the directory
setfacl -d -m g:sysops:rwx /sysops/data
setfacl -d -m u::rwx /sysops/data
setfacl -d -m g::rwx /sysops/data
# Verify ACLs
getfacl /sysops/data
Enter fullscreen mode Exit fullscreen mode
3. Mounting with SGID Support
For NFS-mounted directories, ensure SGID is supported:
# /etc/fstab entry with proper options
server:/exports/data /sysops/data nfs defaults,noatime 0 0
# Mount with specific options
mount -o defaults,sgid /dev/sdb1 /sysops/data
Enter fullscreen mode Exit fullscreen mode
4. Automated User Onboarding
#!/bin/bash
# Add users to the sysops group automatically
add_user_to_sysops() {
local username=$1
# Check if user exists
if id "$username" &>/dev/null; then
usermod -aG sysops "$username"
echo "✓ $username added to sysops group"
else
echo "✗ $username does not exist"
return 1
fi
}
# Usage
add_user_to_sysops "john"
add_user_to_sysops "jane"
add_user_to_sysops "bob"
Enter fullscreen mode Exit fullscreen mode
10. Conclusion
What We’ve Accomplished
Task Command Status Create groupgroupadd sysops
✅
Create directory
mkdir -p /sysops/data
✅
Set group ownership
chgrp -R sysops /sysops/data
✅
Set permissions
chmod 770 /sysops/data
✅
Enable SGID
chmod g+s /sysops/data
✅
Add users to group
usermod -aG sysops user
✅
Test SGID inheritance
touch /sysops/data/test
✅
Key Takeaways
- SGID is essential for collaborative directories
- Permissions 770 ensures group-only access
- Files inherit group automatically with SGID
- Users must be in the group to access files
- Testing is critical to verify configuration
The Complete Solution
# Complete one-liner
groupadd sysops && mkdir -p /sysops/data && chgrp -R sysops /sysops/data && chmod 770 /sysops/data && chmod g+s /sysops/data
# Verification
ls -ld /sysops/data
# Output: drwxrws--- 2 root sysops 4096 Sep 1 10:00 /sysops/data
Enter fullscreen mode Exit fullscreen mode
Benefits of This Configuration
Benefit Description Automatic Group Inheritance All files belong tosysops group
Simplified Collaboration
Team members can access all files
Security
Only group members have access
Reduced Admin Work
No manual permission changes needed
Consistency
All files follow the same permission model
Related Topics
- ACLs (Access Control Lists): For more granular permissions
- Sticky Bit: For preventing file deletion by non-owners
- SUID: For executing files with the owner’s privileges
- Umask: For setting default file permissions
Automation Tools
Tool Purpose Ansible Infrastructure as code Puppet Configuration management Chef Automation platform SaltStack Remote executionAppendix: Quick Reference
Commands Quick Reference
Command Purposegetent group sysops
Check if group exists
groupadd sysops
Create group
mkdir -p /sysops/data
Create directory
chgrp -R sysops /sysops/data
Set group ownership
chmod 770 /sysops/data
Set permissions
chmod g+s /sysops/data
Set SGID
ls -ld /sysops/data
View permissions
usermod -aG sysops user
Add user to group
Permission Quick Reference
Octal Symbolic Description700
rwx------
Owner only
770
rwxrwx---
Owner + Group
2770
rwxrws---
Owner + Group + SGID
750
rwxr-x---
Owner (full), Group (read/execute)
755
rwxr-xr-x
Owner (full), Group (read/execute), Others (read/execute)