Home / Alt manpages / passwd(5)

  • passwd(5)
  • File format
  • linux

Edit /etc/passwd Safely and Verify Every Field

You will inspect an account, understand all seven fields in /etc/passwd, make a controlled edit with the shadow-utils locking tool, and verify the result. Allow about fifteen minutes. You need a shell and sudo access for the edit and integrity check. Reading an account with getent is normally unprivileged.

The examples match shadow-utils 4.13, installed here as Debian package passwd version 1:4.13+dfsg1-4ubuntu3.2. The file format is simple, but a malformed line can stop account-management tools working and can affect logins. Make a backup before changing it.

1. Confirm the account source and inspect one record

Use getent rather than reading only the local file. Name-service configuration can combine local accounts with other sources, so this shows the record that the system lookup returns:

$ getent passwd "$USER"
andy:x:1004:1004:Andy Dixon:/home/andy:/bin/bash

Your login name, numeric IDs, comment, home directory and shell will differ. The output is one colon-delimited record. Treat the password field as sensitive even when it contains only a marker.

Checkpoint: confirm the command you are about to edit and its package version:

$ command -v vipw
/usr/sbin/vipw
$ dpkg-query -W -f='${Package} ${Version}\n' passwd
passwd 1:4.13+dfsg1-4ubuntu3.2

2. Read the seven fields without exposing password data

Each local /etc/passwd line has exactly seven fields. They are, in order:

FieldMeaningOperational consequence
1Login nameThe name used to identify the account.
2Password marker or valueUsually x, meaning the encrypted password is in /etc/shadow.
3User IDThe numeric identity used by the kernel for file ownership and permissions.
4Group IDThe account's primary numeric group.
5Comment or GECOSDisplay information used by utilities. An ampersand can expand to the capitalised login name when displayed.
6Home directoryThe initial directory and the usual value of $HOME at login.
7Command interpreterThe initial program and the usual value of $SHELL. An empty field defaults to /bin/sh.

To review the non-password fields for the current account, use:

$ getent passwd "$USER" | awk -F: '{printf "login=%s uid=%s gid=%s gecos=%s home=%s shell=%s\n", $1, $3, $4, $5, $6, $7}'
login=andy uid=1004 gid=1004 gecos=Andy Dixon home=/home/andy shell=/bin/bash

Do not infer that x is a password. It is a pointer to shadowed password storage, and the manual requires a corresponding entry in /etc/shadow. A blank password field means no password is required by the file format, although some applications refuse all access for such an account. A field beginning with ! is locked; a value such as ! or * prevents Unix-password login while other authentication methods may still work.

3. Take a recoverable backup

Changing /etc/passwd is security-sensitive. Before opening the editor, create a separate backup with the same metadata:

$ sudo cp --preserve=all /etc/passwd /etc/passwd.before-edit
$ sudo ls -l /etc/passwd /etc/passwd.before-edit

Do not edit the backup. Keep it until the account lookup and integrity check succeed. The shadow tools also use /etc/passwd- as a backup, but the manual warns that not every user and password management tool uses that file, so do not assume it is the backup you just made.

4. Edit with vipw and preserve the record shape

Run the editor through vipw. It applies the appropriate lock while the file is open, reducing the chance that another account-management operation writes over your change:

$ sudo vipw

Change only the field you have a clear reason to change. A valid synthetic record has this shape:

login:x:1001:1001:Example User:/home/login:/bin/bash

Keep the seven fields and their colons. Do not put a colon inside the login name, and do not invent a numeric UID or GID that duplicates an existing identity. Changing a UID changes which files are owned by that numeric identity; it does not automatically rename ownership on disk. Changing the home directory or shell can make the next login fail. To change a password, use the passwd command or another account-management tool rather than typing a password hash into this file.

If your preferred editor is not the default, set VISUAL or EDITOR before invoking vipw. The tool checks VISUAL, then EDITOR, then falls back to vi:

$ sudo env VISUAL=nano vipw

Checkpoint: save and exit only after counting seven fields on the changed line. vipw should then release its lock. If you decide not to change anything, exit the editor without saving.

5. Verify the lookup and file integrity

Ask the name-service lookup for the account again. This is a normal command, but it reads the live configuration:

$ getent passwd login
login:x:1001:1001:Example User:/home/login:/bin/bash

Replace login with the account you changed. Then run the shadow-utils checker in read-only mode. It checks field counts, names, IDs, primary groups, home directories, shells, and, when /etc/shadow exists, the correspondence between the two files:

$ sudo pwck --read-only
$ printf 'exit status: %s\n' "$?"
exit status: 0

No output and exit status 0 is the clean result. Warnings need investigation even when the file can still be parsed. Do not answer prompts to delete records as part of a first verification pass; the read-only option is there to prevent an accidental repair.

6. Recover if the edit was wrong

Stop before attempting a second edit if getent cannot find the account, pwck reports the wrong number of fields, or the shell and home directory are clearly incorrect. Restore the backup you made in step 3:

$ sudo cp --preserve=all /etc/passwd.before-edit /etc/passwd
$ sudo pwck --read-only

This restores the whole file, so it also removes any legitimate changes made by another administrator after your backup. Check the backup timestamp and coordinate with anyone else managing the host before using the command. If the machine is already unable to authenticate accounts, use its documented recovery or console procedure rather than repeatedly editing a damaged file.

Done means

  • You confirmed the installed shadow-utils and passwd package version.
  • You inspected the target account with getent and did not expose a password hash.
  • You preserved all seven colon-delimited fields and edited through vipw.
  • getent returns the intended record and sudo pwck --read-only exits 0.
  • Your pre-edit backup remains available until the change has been checked.