Edit /etc/passwd Safely and Verify Every Field
You will inspect an account, understand all seven fields in /etc/passwd, make a controlled edit with the shadow-utils locking tool, and verify the result. Allow about fifteen minutes. You need a shell and sudo access for the edit and integrity check. Reading an account with getent is normally unprivileged.
The route
Jump straight to the step you need, or tick off Done means at the end.
The examples match shadow-utils 4.13, installed here as Debian package passwd version 1:4.13+dfsg1-4ubuntu3.2. The file format is simple, but a malformed line can stop account-management tools working and can affect logins. Make a backup before changing it.
1. Confirm the account source and inspect one record
Use getent rather than reading only the local file. Name-service configuration can combine local accounts with other sources, so this shows the record that the system lookup returns:
$ getent passwd "$USER"
andy:x:1004:1004:Andy Dixon:/home/andy:/bin/bash
Your login name, numeric IDs, comment, home directory and shell will differ. The output is one colon-delimited record. Treat the password field as sensitive even when it contains only a marker.
Checkpoint: confirm the command you are about to edit and its package version:
$ command -v vipw
/usr/sbin/vipw
$ dpkg-query -W -f='${Package} ${Version}\n' passwd
passwd 1:4.13+dfsg1-4ubuntu3.2
2. Read the seven fields without exposing password data
Each local /etc/passwd line has exactly seven fields. They are, in order:
| Field | Meaning | Operational consequence |
|---|---|---|
| 1 | Login name | The name used to identify the account. |
| 2 | Password marker or value | Usually x, meaning the encrypted password is in /etc/shadow. |
| 3 | User ID | The numeric identity used by the kernel for file ownership and permissions. |
| 4 | Group ID | The account's primary numeric group. |
| 5 | Comment or GECOS | Display information used by utilities. An ampersand can expand to the capitalised login name when displayed. |
| 6 | Home directory | The initial directory and the usual value of $HOME at login. |
| 7 | Command interpreter | The initial program and the usual value of $SHELL. An empty field defaults to /bin/sh. |
To review the non-password fields for the current account, use:
$ getent passwd "$USER" | awk -F: '{printf "login=%s uid=%s gid=%s gecos=%s home=%s shell=%s\n", $1, $3, $4, $5, $6, $7}'
login=andy uid=1004 gid=1004 gecos=Andy Dixon home=/home/andy shell=/bin/bash
Do not infer that x is a password. It is a pointer to shadowed password storage, and the manual requires a corresponding entry in /etc/shadow. A blank password field means no password is required by the file format, although some applications refuse all access for such an account. A field beginning with ! is locked; a value such as ! or * prevents Unix-password login while other authentication methods may still work.
3. Take a recoverable backup
Changing /etc/passwd is security-sensitive. Before opening the editor, create a separate backup with the same metadata:
$ sudo cp --preserve=all /etc/passwd /etc/passwd.before-edit
$ sudo ls -l /etc/passwd /etc/passwd.before-edit
Do not edit the backup. Keep it until the account lookup and integrity check succeed. The shadow tools also use /etc/passwd- as a backup, but the manual warns that not every user and password management tool uses that file, so do not assume it is the backup you just made.
4. Edit with vipw and preserve the record shape
Run the editor through vipw. It applies the appropriate lock while the file is open, reducing the chance that another account-management operation writes over your change:
$ sudo vipw
Change only the field you have a clear reason to change. A valid synthetic record has this shape:
login:x:1001:1001:Example User:/home/login:/bin/bash
Keep the seven fields and their colons. Do not put a colon inside the login name, and do not invent a numeric UID or GID that duplicates an existing identity. Changing a UID changes which files are owned by that numeric identity; it does not automatically rename ownership on disk. Changing the home directory or shell can make the next login fail. To change a password, use the passwd command or another account-management tool rather than typing a password hash into this file.
If your preferred editor is not the default, set VISUAL or EDITOR before invoking vipw. The tool checks VISUAL, then EDITOR, then falls back to vi:
$ sudo env VISUAL=nano vipw
Checkpoint: save and exit only after counting seven fields on the changed line. vipw should then release its lock. If you decide not to change anything, exit the editor without saving.
5. Verify the lookup and file integrity
Ask the name-service lookup for the account again. This is a normal command, but it reads the live configuration:
$ getent passwd login
login:x:1001:1001:Example User:/home/login:/bin/bash
Replace login with the account you changed. Then run the shadow-utils checker in read-only mode. It checks field counts, names, IDs, primary groups, home directories, shells, and, when /etc/shadow exists, the correspondence between the two files:
$ sudo pwck --read-only
$ printf 'exit status: %s\n' "$?"
exit status: 0
No output and exit status 0 is the clean result. Warnings need investigation even when the file can still be parsed. Do not answer prompts to delete records as part of a first verification pass; the read-only option is there to prevent an accidental repair.
6. Recover if the edit was wrong
Stop before attempting a second edit if getent cannot find the account, pwck reports the wrong number of fields, or the shell and home directory are clearly incorrect. Restore the backup you made in step 3:
$ sudo cp --preserve=all /etc/passwd.before-edit /etc/passwd
$ sudo pwck --read-only
This restores the whole file, so it also removes any legitimate changes made by another administrator after your backup. Check the backup timestamp and coordinate with anyone else managing the host before using the command. If the machine is already unable to authenticate accounts, use its documented recovery or console procedure rather than repeatedly editing a damaged file.
Done means
- You confirmed the installed shadow-utils and
passwdpackage version. - You inspected the target account with
getentand did not expose a password hash. - You preserved all seven colon-delimited fields and edited through
vipw. getentreturns the intended record andsudo pwck --read-onlyexits 0.- Your pre-edit backup remains available until the change has been checked.