Updated: 28 September 2026 · Applies to: Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9
passwd: Authentication token manipulation error means the system could not write the new password. The usual causes and fixes on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9:
- The file system is read-only. Check with
mount | grep " / "(look forro). Remount it:mount -o remount,rw /. If it went read-only by itself, the disk has errors: checkdmesgand contact support. - The disk is full. Check
df -h /and free some space. - The password files are locked or damaged. Check
lsattr /etc/shadow /etc/passwd; if ani(immutable) flag is shown, remove it withchattr -i /etc/shadow. Runpwckto find damaged entries. - Wrong permissions or SELinux label on
/etc/shadow. Restore them:chmod 000 /etc/shadow(AlmaLinux/Rocky) orchmod 640 /etc/shadow && chown root:shadow /etc/shadow(Ubuntu/Debian), andrestorecon -v /etc/shadowon AlmaLinux/Rocky. - The new password is rejected by the password rules (too short, too similar). The message is then usually preceded by a hint; choose a stronger password.
Note: An immutable /etc/shadow that you did not set yourself can be a sign that someone tampered with the server. Check for other signs of compromise (see "Three Tools to Scan a Linux Server for Viruses, Malware and Rootkits").
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
