Elementary Overview
On Linux, chpasswd changes passwords for multiple existing user accounts from standard input. It is the batch-oriented counterpart to passwd: instead of opening an interactive password prompt for one account at a time, chpasswd reads lines in the form username:password and applies the changes in one administrative workflow. That makes it useful in controlled provisioning, lab automation, and other environments where several local accounts must be updated together. The upstream chpasswd manual describes it specifically as a batch password-update command and notes that it is intended for larger account-creation environments.
Basic Syntax and a Safe Lab Example
The input format is simple: one existing username, a colon, and the new password on each line. A lab-only example is printf '%s\n' 'alice:ExampleOnly-ChangeMe' | sudo chpasswd. After the command succeeds, verify the account itself with getent and inspect password-aging state with chage -l. Do not treat the example password as a real credential, and do not paste production secrets directly into shell commands that may be retained in history, logs, terminal capture, or automation output. In real administration, the important skill is not merely knowing the syntax; it is controlling where the secret comes from and where it can leak.
How chpasswd Fits With PAM and /etc/shadow
By default, chpasswd accepts clear-text passwords on standard input and normally relies on PAM to perform the password update and encryption work. Local password hashes and aging metadata are associated with /etc/shadow, the same protected account database discussed in Linux Command #44 — chage. The command also has an -e option for input that is already encrypted, but that option changes what chpasswd expects; it does not magically make a plain-text password safe. The Linux-PAM documentation explains that PAM provides the common authentication and password-management framework used by system tools, while the chpasswd manual documents /etc/pam.d/chpasswd as the command’s PAM configuration file.
Batch Updates, Errors, and Verification
chpasswd is valuable because one input stream can describe many password changes, but batch work increases the cost of a mistake. The manual notes an important implementation detail: when PAM performs the updates, a failure for one user can be reported while processing continues for later users; in non-PAM password encryption paths, the utility can stage changes and commit them only after checking the set. Either way, automation should check the command’s exit status and then verify the intended accounts. Pair chpasswd with the account-management commands already covered in this series: useradd creates accounts, usermod changes account properties, userdel removes accounts, and chpasswd updates passwords at batch scale.
Practical Command Set
sudo chpasswd— readusername:passwordpairs from standard input.printf '%s\n' 'alice:ExampleOnly-ChangeMe' | sudo chpasswd— update one lab account non-interactively.sudo chpasswd < secure-input.txt— read multiple account/password pairs from an input file; protect and remove that file appropriately because it may contain secrets.sudo chpasswd -e— tellchpasswdthat supplied passwords are already encrypted hashes.sudo chage -l alice— inspect password-aging information after a change.getent passwd alice— confirm the account exists through the Name Service Switch path.echo $?— inspect the previous command’s exit status in an interactive shell.
Exercises
- Create two disposable lab users with
useradd. - Prepare two
username:passwordlines using throwaway lab passwords and apply them withchpasswd. - Check the exit status immediately after the batch update.
- Verify both accounts with
getent passwd USER. - Inspect each account with
chage -l USERand identify the last-password-change field. - Explain why a command that accepts passwords through standard input still requires careful secret handling.
- Explain what changes when
chpasswd -eis used.
Knowledge Check + Answers
- What format does
chpasswdread? Oneusername:passwordpair per line. - What is the main difference between
passwdandchpasswd?passwdis normally interactive and account-by-account;chpasswdis designed for non-interactive batch updates. - What does
-emean? The supplied password field is already encrypted rather than clear text. - Which protected file is central to local Linux password hashes and aging metadata?
/etc/shadow. - Why should automation check the exit status? A batch workflow can fail for one or more account updates, so successful execution should be verified rather than assumed.
- Which earlier command is useful for reviewing password aging after a batch change?
chage -l USER.
Elementary Conclusion
chpasswd is the Linux tool for changing many local account passwords through one controlled input stream. Its syntax is easy; secure use is about protecting the secret input, checking the result, and verifying the affected accounts. After learning passwd for individual password changes and chage for password-aging policy, chpasswd adds the batch-administration piece of the same Linux account-management workflow.
BitcoinVersus.Tech
Editor’s Note:
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on technical and financial subjects purely for informational purposes.

Leave a comment