Reviewing /etc/passwd you find some service accounts with /usr/sbin/nologin as their shell and others with /bin/false. Both prevent an interactive login. What does nologin do that /bin/false does not?
LPIC-1 Exam 102-500, objective 107. Administrative tasks medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct It prints a message explaining that the account is unavailable — taken from /etc/nologin.txt when that file exists — before exiting with a non-zero status.
Correct. That courtesy message is nologin's entire purpose; /bin/false simply exits with status 1 and says nothing, leaving the user with a connection that closes silently.
Not correct It permits non-interactive uses such as su -c and scp, which /bin/false blocks.
Wrong. Both are equally effective at blocking anything that needs a shell, including scp and `su -c`, because both refuse to execute the command they are handed.
Not correct It prevents the account from being used by any daemon, whereas /bin/false only blocks logins.
Wrong. Neither shell restricts what a daemon does. A service running as that account never invokes the login shell at all, which is why setting nologin is safe for service accounts.
Not correct It locks the account's password in /etc/shadow as a side effect of the first refused login.
Wrong. Neither shell touches /etc/shadow. Locking the password is a separate step, done with passwd -l or usermod -L.
Why
Both entries work by the same mechanism: the seventh field of /etc/passwd is executed as the login shell, and a program that immediately exits non-zero ends the session. The difference is only whether the user is told why. Two further points that exams like: neither shell prevents SSH public-key authentication from succeeding for other purposes such as port forwarding, and the unrelated file /etc/nologin — no .txt — blocks logins for all non-root users while it exists.
Where this comes from
- Cited
- manual page nologin(8)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked