Updated: 28 September 2026 · Applies to: Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9

passwd: Authentication token manipulation error means the system could not write the new password. The usual causes and fixes on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9:

  1. The file system is read-only. Check with mount | grep " / " (look for ro). Remount it: mount -o remount,rw /. If it went read-only by itself, the disk has errors: check dmesg and contact support.
  2. The disk is full. Check df -h / and free some space.
  3. The password files are locked or damaged. Check lsattr /etc/shadow /etc/passwd; if an i (immutable) flag is shown, remove it with chattr -i /etc/shadow. Run pwck to find damaged entries.
  4. Wrong permissions or SELinux label on /etc/shadow. Restore them: chmod 000 /etc/shadow (AlmaLinux/Rocky) or chmod 640 /etc/shadow && chown root:shadow /etc/shadow (Ubuntu/Debian), and restorecon -v /etc/shadow on AlmaLinux/Rocky.
  5. The new password is rejected by the password rules (too short, too similar). The message is then usually preceded by a hint; choose a stronger password.

Note: An immutable /etc/shadow that you did not set yourself can be a sign that someone tampered with the server. Check for other signs of compromise (see "Three Tools to Scan a Linux Server for Viruses, Malware and Rootkits").

Ucartz services for this topic

Was this answer helpful? 5553 Users Found This Useful (5555 Votes)