Linux Command #45 – chpasswd (Linux OS)

Colored-pencil illustration of a Linux administrator securely managing multiple user accounts from a terminal.

Elementary Overview

On Linux, chpasswd changes passwords for multiple existing user accounts from standard input. It is the batch-oriented counterpart to passwd: instead of opening an interactive password prompt for one account at a time, chpasswd reads lines in the form username:password and applies the changes in one administrative workflow. That makes it useful in controlled provisioning, lab automation, and other environments where several local accounts must be updated together. The upstream chpasswd manual describes it specifically as a batch password-update command and notes that it is intended for larger account-creation environments.

Bóson Treinamentos — chpasswd batch password changes on Linux.

Basic Syntax and a Safe Lab Example

The input format is simple: one existing username, a colon, and the new password on each line. A lab-only example is printf '%s\n' 'alice:ExampleOnly-ChangeMe' | sudo chpasswd. After the command succeeds, verify the account itself with getent and inspect password-aging state with chage -l. Do not treat the example password as a real credential, and do not paste production secrets directly into shell commands that may be retained in history, logs, terminal capture, or automation output. In real administration, the important skill is not merely knowing the syntax; it is controlling where the secret comes from and where it can leak.

Linux Vasanth — chpasswd in bulk mode.

How chpasswd Fits With PAM and /etc/shadow

By default, chpasswd accepts clear-text passwords on standard input and normally relies on PAM to perform the password update and encryption work. Local password hashes and aging metadata are associated with /etc/shadow, the same protected account database discussed in Linux Command #44 — chage. The command also has an -e option for input that is already encrypted, but that option changes what chpasswd expects; it does not magically make a plain-text password safe. The Linux-PAM documentation explains that PAM provides the common authentication and password-management framework used by system tools, while the chpasswd manual documents /etc/pam.d/chpasswd as the command’s PAM configuration file.

Red Hat Enterprise Linux — account security, password resets, and PAM.

Batch Updates, Errors, and Verification

chpasswd is valuable because one input stream can describe many password changes, but batch work increases the cost of a mistake. The manual notes an important implementation detail: when PAM performs the updates, a failure for one user can be reported while processing continues for later users; in non-PAM password encryption paths, the utility can stage changes and commit them only after checking the set. Either way, automation should check the command’s exit status and then verify the intended accounts. Pair chpasswd with the account-management commands already covered in this series: useradd creates accounts, usermod changes account properties, userdel removes accounts, and chpasswd updates passwords at batch scale.

ComputerConcepts — Linux user management, password changes, and account lifecycle basics.

Practical Command Set

  • sudo chpasswd — read username:password pairs from standard input.
  • printf '%s\n' 'alice:ExampleOnly-ChangeMe' | sudo chpasswd — update one lab account non-interactively.
  • sudo chpasswd < secure-input.txt — read multiple account/password pairs from an input file; protect and remove that file appropriately because it may contain secrets.
  • sudo chpasswd -e — tell chpasswd that supplied passwords are already encrypted hashes.
  • sudo chage -l alice — inspect password-aging information after a change.
  • getent passwd alice — confirm the account exists through the Name Service Switch path.
  • echo $? — inspect the previous command’s exit status in an interactive shell.

Exercises

  1. Create two disposable lab users with useradd.
  2. Prepare two username:password lines using throwaway lab passwords and apply them with chpasswd.
  3. Check the exit status immediately after the batch update.
  4. Verify both accounts with getent passwd USER.
  5. Inspect each account with chage -l USER and identify the last-password-change field.
  6. Explain why a command that accepts passwords through standard input still requires careful secret handling.
  7. Explain what changes when chpasswd -e is used.

Knowledge Check + Answers

  1. What format does chpasswd read? One username:password pair per line.
  2. What is the main difference between passwd and chpasswd? passwd is normally interactive and account-by-account; chpasswd is designed for non-interactive batch updates.
  3. What does -e mean? The supplied password field is already encrypted rather than clear text.
  4. Which protected file is central to local Linux password hashes and aging metadata? /etc/shadow.
  5. Why should automation check the exit status? A batch workflow can fail for one or more account updates, so successful execution should be verified rather than assumed.
  6. Which earlier command is useful for reviewing password aging after a batch change? chage -l USER.

Elementary Conclusion

chpasswd is the Linux tool for changing many local account passwords through one controlled input stream. Its syntax is easy; secure use is about protecting the secret input, checking the result, and verifying the affected accounts. After learning passwd for individual password changes and chage for password-aging policy, chpasswd adds the batch-administration piece of the same Linux account-management workflow.

DevOps Guy Dikshant — Linux user and password-management workflow.

BitcoinVersus.Tech

Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This media platform reports on technical and financial subjects purely for informational purposes.

Leave a comment