Linux Command #37 – passwd (Linux OS)

Minimal black and neon-green Linux illustration representing passwd and user password administration.

The Linux passwd command changes account passwords and gives administrators several controls for locking, unlocking, expiring, and inspecting password state.

In Linux Command #36 – getent, we queried account information from Linux system databases. passwd moves from lookup to account maintenance: it changes authentication credentials for your own account or, with appropriate privileges, another local account.

Change your own password

passwd

Run passwd without a username to change the password for the account you are currently using. The command normally asks for your current password and then prompts for the new password twice.

Passwords are not displayed while you type them. A blank-looking prompt does not mean the keyboard stopped working; the terminal intentionally avoids echoing the password.

Video 1: Using the passwd command

Learn Linux TV demonstrates the passwd command, including changing your own password and administering another user’s password.

Change another user’s password

sudo passwd alex

An administrator can specify a username. With sudo, this example sets a new password for the account named alex. The administrator is asked to enter and confirm the new password rather than needing to know the user’s existing password.

This is useful when provisioning a local account or resetting credentials, but it should be handled according to the organization’s access-control procedures.

Check password status

passwd -S
sudo passwd -S alex

The -S option reports password status. Depending on the Linux distribution, the output can include whether the account has a usable password, when it was last changed, and password-aging values.

Lock and unlock a password

sudo passwd -l alex
sudo passwd -u alex

-l locks the account’s password by making the stored password hash unusable for normal password authentication. -u unlocks it. Locking a password is not always the same as disabling every possible way an account could authenticate, so administrators should understand the system’s SSH keys, PAM configuration, and other login methods.

Video 2: Linux account security and PAM

Red Hat Enterprise Linux explains account maintenance and the PAM framework that sits underneath Linux password and authentication workflows.

Expire a password

sudo passwd -e alex

The -e option expires the password immediately. On a typical password-login workflow, that forces the user to choose a new password the next time the account authenticates through a path that honors password expiration.

Delete a stored password carefully

sudo passwd -d alex

The -d option removes the account’s password. This is an administrative operation and should not be confused with locking an account. Depending on system policy, an account without a password may behave differently from a locked account, so do not use this option casually on production systems.

Where Linux stores account information

Basic account metadata appears in /etc/passwd, while password hashes and password-aging information for local accounts are normally stored in the protected /etc/shadow file. Regular users should not be able to read the shadow file directly.

getent passwd "$USER"
sudo passwd -S "$USER"

This pairs the previous lesson with the current one: getent looks up the account, while passwd reports or changes password state.

Video 3: User and group administration

Verified education channel ProgrammingKnowledge provides a dedicated Linux passwd tutorial that reinforces password-changing syntax and command-line usage.

A technician workflow

Suppose a local maintenance account exists on a Linux management server but the technician cannot authenticate with its password. Start by confirming the account and then inspect its password state before changing anything:

getent passwd technician
sudo passwd -S technician

If the account exists and the password is locked or expired, the status output gives you evidence before you decide whether the approved fix is an unlock, password reset, or expiration change. This is safer than immediately overwriting credentials without checking the account state.

Useful passwd options

  • passwd — change your own password.
  • sudo passwd USER — set another local user’s password.
  • passwd -S — display password status.
  • sudo passwd -l USER — lock password authentication for an account.
  • sudo passwd -u USER — unlock the password.
  • sudo passwd -e USER — expire the password now.
  • sudo passwd -d USER — delete the stored password; use with care.

Common beginner mistakes

  • Thinking nothing is being typed because password characters are hidden.
  • Confusing the /etc/passwd account database with the passwd command.
  • Assuming passwd -l disables every possible authentication method.
  • Resetting another user’s password before checking whether the account is locked or expired.
  • Using passwd -d when the real goal is to lock an account.
  • Changing production credentials without following the site’s access-control and change procedures.

Practice

  1. Run passwd -S for your own account.
  2. Run getent passwd "$USER" and compare the account information with the password-status output.
  3. On a disposable lab VM, create or use a test account and inspect it with sudo passwd -S USER.
  4. If permitted in your lab, lock and unlock only that test account and observe how the status changes.
  5. Explain in one sentence why locking a password is not necessarily identical to disabling an entire account.

Key takeaway

passwd is more than a password-change command. It also lets administrators inspect, lock, unlock, expire, and remove local password credentials. Use the status option first when troubleshooting, understand that password state is only one part of Linux authentication, and make administrative changes only through an approved workflow.

Leave a comment