Cybersecurity Triage
Read-only, sensitive outputFind SSH Keys for nologin Users
You need to spot accounts that have authorized_keys files even though their passwd shell is nologin.
Command
comm -12 <(awk -F: '$7 !~ /(bash|sh|zsh)$/ {print $1}' /etc/passwd | sort) <(find /home -path '*/.ssh/authorized_keys' -printf '%h\n' 2>/dev/null | awk -F/ '{print $(NF-1)}' | sort)
Before you run this
System impact: Read-only. Output may expose users, paths, tokens, keys, IPs, process arguments, or log details.
When not to use it: Do not assume every match is exploitable; SSH daemon options, forced commands, and account policy can change behavior.
Expected output
Account names that are nologin in passwd but still have authorized_keys files.
System impact
Read-only, sensitive output. Nothing changes. The command compares system passwd accounts with authorized_keys owners.
May require elevated permissions on protected paths or service-owned files.
Recovery / rollback: no state is changed.
When to use it
Use when checking for stale SSH key files after service account changes or offboarding.
When not to use it
Do not assume every match is exploitable; SSH daemon options, forced commands, and account policy can change behavior.
next steps
Related commands
Find SSH Key Users with sudo
The highest-priority access review starts where SSH keys and sudo overlap.
comm -12 <(find /home -path '*/.ssh/authorized_keys' -printf '%h\n' 2>/dev/null | awk -F/ '{print $(NF-1)}' | sort) <(awk -F: '$1=="sudo" {gsub(",","\n",$4); print $4}' /etc/group | sort)
Count authorized_keys by User
authorized_keys is the practical SSH access list.
find /home -path '*/.ssh/authorized_keys' -exec sh -c 'for f do user=$(basename "$(dirname "$(dirname "$f")")"); keys=$(grep -vc "^[[:space:]]*#" "$f"); printf "%s %s %s\n" "$user" "$keys" "$f"; done' sh {} + 2>/dev/null | sort
Summarize SSH Authorized Key Types
Key inventory gets more useful when old key types stand out.
find /home -path '*/.ssh/authorized_keys' -exec awk '{print $1}' {} + 2>/dev/null | sort | uniq -c | sort -nr
Find Loose authorized_keys Modes
SSH key access files should not be looser than intended.
find /home -path '*/.ssh/authorized_keys' -printf '%m %p\n' 2>/dev/null | awk '$1 > 600'
Inventory SSH authorized_keys
authorized_keys files are the practical list of who can use key-based SSH.
find /home -path '*/.ssh/authorized_keys' -exec awk '{print FILENAME, $1, $NF}' {} + 2>/dev/null
Study mapping
Use this as independent command practice: read the notes, predict the output, then compare it with the example before using a real shell.
Independent study support only. No affiliation, endorsement, exam dumps, or real exam questions.