Home / Alt manpages / passwd(1)

  • passwd(1)
  • User command
  • linux

Change Linux Passwords Safely with passwd

By the end of this guide you will be able to change a Linux password interactively, check its ageing status, and carry out the common administrator actions without exposing a secret in shell history. The examples match the installed passwd from shadow-utils 4.13. Allow about five minutes for a normal change, plus time to investigate PAM or account policy errors.

Before you start

  1. Use an interactive terminal on the machine whose account you are changing. passwd reads passwords without displaying them; do not put a password after the command or in a script.
  2. Know which account you intend to change. A normal user can change only their own password. An administrator with suitable privilege can change another account's password.
  3. Keep a working session open while testing an administrative change. A bad password, an account lock, or a failed remote login can otherwise leave you without access.

Checkpoint

The ordinary self-service command needs no sudo. Administrative commands below do.

1. Change your own password

Run:

passwd

For an account that already has a password, enter the current password once, then enter the new password twice. Nothing is echoed. The command checks the site's PAM policy and refuses a password that does not meet that policy.

Changing password for alice.
(current) UNIX password:
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully

The exact prompts can differ because passwd uses PAM, normally configured through /etc/pam.d/passwd. A mismatch, an incorrect current password, or a policy rejection leaves the existing password unchanged. Do not keep retrying blindly: read the error and check whether the account has a minimum change interval.

Checkpoint

Verify success from the command's exit status, without printing a password:

passwd
printf 'passwd exit status: %s\n' "$?"

A successful run reports exit status 0. If the command exits with 1, permission was denied; 3 means an unexpected failure where nothing was done. The other documented statuses cover invalid options or arguments, a missing password file, and a busy password file.

2. Set a password for another account

This changes account state and requires administrator privilege:

sudo passwd alice

Replace alice with the exact login name. The administrator is allowed to bypass the old-password prompt, but the replacement is still entered twice and is still subject to the configured password checks.

Security warning

This is a credential change. Confirm the account name before submitting the new password, tell the account owner through a trusted channel, and do not send the password through chat or place it in a ticket. If the account is used by a service, changing its password can interrupt that service until its stored credential is updated.

If the command fails, check the account and the local policy rather than trying password variants in public logs:

getent passwd alice
sudo passwd --status alice

getent confirms that the name resolves through the system's account sources. The status command is read-only and is useful before and after an administrative change.

3. Read password ageing status

Inspect one account with:

passwd --status alice

Typical output has seven fields: the login name; P for a usable password, L for a locked password, or NP for no password; the last-change date; then minimum age, maximum age, warning period, and inactivity period in days. The date and numeric values describe policy, not the password itself.

To inspect every account, an administrator can use:

sudo passwd --all --status

Checkpoint

Use this status output to distinguish a forgotten password from a locked account. Do not assume that L disables every login method: the manpage notes that another authentication token, such as an SSH key, may still work.

4. Force a change or adjust ageing

To require the named user to choose a new password at the next login:

sudo passwd --expire alice

This changes account state. Confirm the result:

sudo passwd --status alice

Ageing values can also be set explicitly. For example, this permits a change at any time, allows 90 days of validity, and warns for the preceding 14 days:

sudo passwd --mindays 0 --maxdays 90 --warndays 14 alice

Use these values only when they match the site's policy. Passing -1 to --maxdays removes password-validity checking, which can weaken an account's control. The --inactive option sets how many days an expired password may remain before the account can no longer sign in.

5. Recover from a password lock

Locking is not a routine way to disable an account. It modifies the stored password marker, blocks password changes by that user, and does not necessarily stop SSH keys or another authentication token.

sudo passwd --lock alice
sudo passwd --status alice

Warning

Locking is a security-sensitive, potentially service-disrupting action. Check active sessions and alternate access before using it. To undo a lock made with --lock, use:

sudo passwd --unlock alice
sudo passwd --status alice

Unlocking restores the password value saved before the lock. It does not create a new password. If the goal is to disable the account rather than only its password, use the account-management procedure appropriate to the system; the passwd manpage specifically points administrators to usermod --expiredate 1 for that purpose.

Deleting a password is even more dangerous:

sudo passwd --delete alice

This makes the named account passwordless. Do not use it as a password-recovery shortcut. It can permit authentication paths that accept an empty password, depending on the PAM and service configuration. Set a known-good password instead, then verify the account's status.

Common traps and where to look

  • "Authentication token manipulation error": check that the account is writable, that the filesystem is not read-only, and that the PAM configuration is valid.
  • Unexpected policy rejection: password complexity and ageing rules are site-specific. Review the PAM stack and the account's status rather than guessing what the policy should be.
  • Network accounts: NIS or another remote account source may require the change to be made against the correct server.
  • Wrong target: always use passwd --status LOGIN before an administrative change, and quote unusual login names when a shell could interpret characters.

The main local data is held in /etc/passwd and /etc/shadow; the latter contains protected account information. Avoid editing either file by hand for a password change. Use passwd so PAM and the system's password storage rules are applied.

Done means

  • The intended login name was confirmed before any administrative action.
  • The new password was entered interactively and was never placed in a command, script, or log.
  • The command returned exit status 0, or its documented failure was investigated.
  • passwd --status LOGIN shows the expected password state and ageing values.
  • Any temporary lock, forced expiry, or ageing change has been deliberately recorded and has a tested recovery path.