Home / Alt manpages / chgpasswd(8)

  • chgpasswd(8)
  • Admin command
  • linux

Update Group Passwords Safely with chgpasswd

You will finish with a controlled way to set passwords for existing Linux groups in batch mode, using chgpasswd from the Ubuntu passwd package. The guide uses the locally installed package version 1:4.13+dfsg1-4ubuntu3.2. Allow about ten minutes for one group, plus time to check your local password policy.

Privilege checkpoint: changing group account data is an administrative operation. You need root privileges, normally through sudo, and the target group must already exist. The examples below change /etc/gshadow. Have a recovery plan and make sure you are working on the intended host before running the write command.

1. Check the target group

Use an ordinary, read-only command to confirm the group name. Replace GROUP_NAME with the real name; do not include angle brackets or the placeholder itself.

$ getent group GROUP_NAME
GROUP_NAME:x:2001:alice,bob

The numeric ID and member list will differ on your system. If getent prints nothing, stop. chgpasswd updates existing groups; it does not create one. Create or provision the group through your normal identity-management process first.

Checkpoint: confirm that the returned name is the group whose password you intend to change. A typo can select a different existing group, and a directory service may make the result look different from a local /etc/group entry.

2. Read a new password without putting it in the command line

By default, chgpasswd expects each input line to contain a group name, a colon, and a clear-text password. Do not put that password directly in a command that will enter shell history. Read it silently instead:

read -r -s -p 'New group password: ' NEW_GROUP_PASSWORD
printf '\n'
printf '%s:%s\n' 'GROUP_NAME' "$NEW_GROUP_PASSWORD" | sudo chgpasswd -c SHA512
status=$?
unset NEW_GROUP_PASSWORD
printf 'chgpasswd status: %s\n' "$status"
exit "$status"

The input is consumed on standard input. The sudo command elevates only chgpasswd, not the shell variable or the prompt. The final unset removes the variable from the current shell. This is still sensitive data while the command runs: use a trusted terminal, avoid recording the session, and never paste a real password into a ticket or chat.

The -c SHA512 option selects the SHA-512 crypt method for clear-text input. The installed help also lists NONE, DES, MD5, SHA256, SHA512 and YESCRYPT as method names. The installed manual documents DES, MD5, NONE, SHA256 and SHA512, and warns that DES and MD5 should not be used for new hashes. Choose a method permitted by your local policy rather than copying this example blindly.

3. Verify the write completed

Immediately after the command, status 0 means the update completed successfully:

chgpasswd status: 0

A non-zero status means the update did not complete as expected. Keep the exact diagnostic and status. Do not retry repeatedly with a password pasted into the terminal. Check the group name, permissions, the selected method, and whether the account database is local or centrally managed.

As root, inspect only the hash format and the group name. Do not print the whole secret-bearing file into a shared log:

sudo awk -F: '$1 == "GROUP_NAME" { print $1 ":" $2 }' /etc/gshadow

For SHA-512, the second field normally begins with $6$, although the exact salt and hash are unique. The password itself cannot be recovered from this field. Treat the complete /etc/gshadow file as confidential anyway, because it contains group security data.

4. Use pre-hashed input only when you have a verified hash

The --encrypted or -e option tells chgpasswd not to hash the supplied value. Each line still has the same group:password shape, but the password field must already be a format accepted by the system's crypt implementation.

printf '%s\n' 'GROUP_NAME:PASTE_A_VERIFIED_CRYPT_HASH_HERE' | sudo chgpasswd --encrypted

This is not a command for a plain password. Mixing up the two modes can either store the wrong value or produce a hash that cannot authenticate. Handle the source hash as a credential, restrict its permissions, and remove temporary files using your organisation's secure procedure after the update.

5. Understand configuration and rollback

When no method is supplied, chgpasswd follows ENCRYPT_METHOD in /etc/login.defs. On this machine that setting is SHA512. The same file can define SHA_CRYPT_MIN_ROUNDS and SHA_CRYPT_MAX_ROUNDS for SHA-256 or SHA-512. The --sha-rounds option accepts 0 for the system default, otherwise the manual enforces a range from 1,000 to 999,999,999. It is valid only with SHA-256 or SHA-512.

Do not edit /etc/login.defs just to repair one group password. The setting affects future group-password generation, not a magic conversion of existing hashes, and user-password generation is handled by PAM. Coordinate any policy change separately.

There is no generic undo flag. Before a change, arrange a recovery path: record the target group, retain an authorised previous crypt hash if policy allows it, or be ready to set a replacement password using the same procedure. If the update caused a service or workflow problem, set a new known-good group password rather than trying to recover the clear text. Do not restore an untrusted copy of /etc/gshadow over the live file.

6. Apply the same operation inside a root directory

-R or --root takes an absolute directory and uses configuration files below it. This is useful for an offline system image, but it is not a dry run. The directory must contain the relevant account files and the command must be able to enter it with the required privilege.

# chgpasswd --root /srv/target-root --crypt-method SHA512 < group-passwords.txt

The input file contains one group:password record per line and must be protected from other users. Test the image workflow on a disposable copy first. An error from --root does not prove the host configuration is broken; it may mean the path is not absolute, the directory is incomplete, or the caller cannot chroot into it.

Done means

  • The group name was checked and the group already existed.
  • The password was supplied through protected standard input, not a shell-history command.
  • The selected crypt method matches local policy and the command returned status 0.
  • The resulting hash was checked without exposing the complete /etc/gshadow file.
  • You know how to set a replacement password if the change must be reversed.