Generate Password Hashes with openssl passwd
You will finish with a repeatable way to generate the password hash formats supported by the installed openssl passwd command, while keeping real passwords out of shell history and terminal output. The examples use OpenSSL 3.6.1, installed on this machine, with the openssl-passwd(1ssl) manpage dated 18 August 2026 and labelled 3.0.13.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need OpenSSL and a shell. No elevated privileges are required, and this guide does not edit account files, web-server configuration or any service. The command computes hashes; it does not check whether a supplied hash matches a password.
1. Check the installed command
Confirm that the expected executable is first in your path and record its version. These are ordinary read-only commands:
$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
Checkpoint: if the path or version differs, keep the output with your change record. Hash formats and available algorithms belong to the command you will actually run, not to a tutorial copied from another host.
Read the local option summary when working on a different installation:
$ openssl passwd -help
Usage: passwd [options] [password]
Input options:
-in infile Read passwords from file
-stdin Read passwords from stdin
Output options:
-table Format output as table
-reverse Switch table columns
The subcommand is named passwd, even though its manual page is openssl-passwd(1ssl). A password argument is optional. When it is omitted, OpenSSL reads from the terminal.
2. Generate one hash without putting the password in history
For a real secret, omit the password argument and let OpenSSL prompt. Choose the algorithm explicitly. SHA-512 crypt is selected with -6:
$ openssl passwd -6
Password:
Verifying - Password:
$6$RANDOM_SALT$GENERATED_HASH
The salt and hash above are placeholders showing the shape of the result. Your output will differ. The password is not displayed while you type it. The second prompt verifies the entry; if the two entries differ, start again with the correct password.
Do not use sudo for this command. Elevated privileges do not improve the hash, and they make it easier to write the result into a protected location by accident. Treat the printed hash as sensitive: it is designed to be stored for later password checking, but anyone who obtains it can attempt guesses offline.
3. Select the format deliberately
The manpage documents five algorithms. -5 selects SHA-256 crypt and -6 selects SHA-512 crypt. -1 is the default and uses the MD5-based BSD password algorithm. -apr1 selects Apache's variant, while -aixmd5 selects the AIX variant.
Use a fixed salt only for a test or a compatibility check. This command makes the result reproducible:
$ openssl passwd -6 -salt xxxxxxxx password
$6$xxxxxxxx$wqnb6MLqmjMU5Hx4wQ0qsgf/VWMnStSJlbRMy5buT2fPUnVASxaE4zm2JBuj6ISxoGFOWhZODdzl2VyW/Ltzz.
This example deliberately uses the literal test password password, so do not copy it into a real account or application. A fixed salt also means the same password produces the same result, which is useful for checking a migration but undesirable as a general practice. For normal use, omit -salt and let the command generate one.
Checkpoint: the result should begin with the algorithm marker, such as $6$, followed by a salt and a final hash separated by dollar signs. A result beginning with $1$, $apr1$ or the AIX form is a different compatibility format, not a stronger spelling of SHA-512.
4. Test safely with standard input
If another program must supply a test value, use -stdin rather than putting the value in the command's positional argument. Standard input is still sensitive, so do not use this pattern with a real password in shell history or a logged pipeline:
$ printf '%s\n' 'password' | openssl passwd -6 -salt xxxxxxxx -stdin
$6$xxxxxxxx$wqnb6MLqmjMU5Hx4wQ0qsgf/VWMnStSJlbRMy5buT2fPUnVASxaE4zm2JBuj6ISxoGFOWhZODdzl2VyW/Ltzz.
That exact output verifies that the local command accepts the expected input path. For an interactive operator workflow, the terminal prompt from step 2 is safer because the secret is not written in the command line. For an application, use its supported password-hashing library and keep the secret inside that application's controlled input path rather than constructing shell commands.
5. Hash a password list
Use -in when each line of a file is a separate password. This changes the handling of every line, so inspect the input file and its permissions before running it. The command itself is ordinary, but the file may contain secrets:
$ openssl passwd -6 -in password-list.txt
$6$generated-salt-1$generated-hash-1
$6$generated-salt-2$generated-hash-2
Output order follows input order. The displayed salts and hashes are illustrative. If the input file is temporary, remove it using your normal approved secure-handling process after checking that no job, shell history entry or log still needs it. Do not paste real passwords into a guide, ticket or terminal recording.
There is no undo for hashing itself: it does not alter the input file. If your workflow created a temporary plaintext list, stop using it, restrict its permissions, and remove it only after confirming that it is no longer needed. Recovery is possible only from another copy of the original passwords; a hash cannot be reversed by this command.
6. Preserve or hide the cleartext in output
The -table option prefixes each hash with the cleartext password and a TAB. This is convenient for a controlled migration test and dangerous in logs, copied output and shared terminals:
$ printf '%s\n' 'password' | openssl passwd -6 -salt xxxxxxxx -stdin -table
password $6$xxxxxxxx$wqnb6MLqmjMU5Hx4wQ0qsgf/VWMnStSJlbRMy5buT2fPUnVASxaE4zm2JBuj6ISxoGFOWhZODdzl2VyW/Ltzz.
-reverse changes that table order to hash first and cleartext second. It does not hide the password:
$ printf '%s\n' 'password' | openssl passwd -6 -salt xxxxxxxx -stdin -table -reverse
$6$xxxxxxxx$wqnb6MLqmjMU5Hx4wQ0qsgf/VWMnStSJlbRMy5buT2fPUnVASxaE4zm2JBuj6ISxoGFOWhZODdzl2VyW/Ltzz. password
Checkpoint: use plain hash output unless a downstream import format explicitly requires the cleartext column. Never use -table in a command whose output is captured by CI logs, shell recording or a shared support session.
7. Understand salts, warnings and removed options
A salt makes identical passwords produce different stored values when salts differ. The command generates a salt when you omit -salt. The manpage also records that specifying -salt implies -noverify for terminal input, so a fixed-salt prompt does not ask for a second copy of the password. Use a fixed salt only when reproducing a known test or compatibility result.
A password supplied directly as the final command-line argument can be exposed through shell history or process inspection. OpenSSL may warn when such passwords are truncated; -quiet suppresses those warnings, but it does not make command-line passwords safe or prevent truncation. Do not use -quiet as a security fix.
The old -crypt option was removed in OpenSSL 3.0. If a script still passes it, update the script for the format its target system actually requires and test the import before changing production data. Do not silently replace it with -1 or -6; those formats are not interchangeable.
Done means
- You checked the installed OpenSSL version and the local
passwdoptions. - You selected an algorithm explicitly instead of relying on the default MD5-based BSD format.
- You used the terminal prompt for a real password and kept it out of the command line.
- You used a fixed salt only for a reproducible test or required compatibility case.
- You avoided
-tableunless a controlled import needed cleartext output. - You have not modified an account, service, configuration file or password list.