Applies to: Ubuntu, Debian, AlmaLinux, Rocky Linux and other Linux servers (the passwd, chpasswd and chage commands)
On Linux you change passwords with the passwd command. Any user can change their own password; the root user (or a user with sudo) can change anyone’s. We tested every command below on Ubuntu 24.04, Debian 13 and AlmaLinux 9.
Change your own password
- Log in over SSH as the user.
- Run
passwd. - Enter your current password, then the new one twice. Nothing appears on screen while you type; that is normal.
You should see password updated successfully (Ubuntu, Debian) or all authentication tokens updated successfully (AlmaLinux, Rocky Linux).
Change another user’s password (root or sudo)
sudo passwd alice # asks for the new password twice, not the old one sudo passwd root # change the root password
Set a password from a script
chpasswd reads user:password pairs, so it works without prompts:
echo 'alice:N3w-Strong-Pass!' | sudo chpasswd
The password ends up in your shell history this way, so clear it afterwards (history -d or history -c), or read it from a protected file instead.
Force a password change at next login
sudo passwd -e alice # expire the password now sudo chage -l alice # "Last password change: password must be changed"
Check, lock and unlock a password
sudo passwd -S alice # status: P = usable password, L or LK = locked sudo passwd -l alice # lock password logins sudo passwd -u alice # unlock
Locking only blocks password logins. The user can still log in with an SSH key, so remove their keys from ~/.ssh/authorized_keys too if you want to shut them out completely.
Choose a strong password
- Use at least 12 characters, or better, a passphrase of several words.
- Use a different password for every server and account; a password manager helps.
- For SSH, key-based login is safer than any password.
Common problems
- passwd: Authentication token manipulation error: usually a full or read-only disk, or damaged password files. See how to fix the authentication token manipulation error.
- BAD PASSWORD: The password is shorter than 8 characters (or similar): the server’s password rules rejected it. Choose a longer, less predictable password.
- Forgot the root password of your Ucartz VPS or server: open a support ticket and our team helps you reset it.
Need users to change their password at first login? See how to force a user to change their password at next login.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
