Applies to: Ubuntu, Debian, AlmaLinux, Rocky Linux and other Linux servers (the passwd, chpasswd and chage commands)

On Linux you change passwords with the passwd command. Any user can change their own password; the root user (or a user with sudo) can change anyone’s. We tested every command below on Ubuntu 24.04, Debian 13 and AlmaLinux 9.

Change your own password

  1. Log in over SSH as the user.
  2. Run passwd.
  3. Enter your current password, then the new one twice. Nothing appears on screen while you type; that is normal.

You should see password updated successfully (Ubuntu, Debian) or all authentication tokens updated successfully (AlmaLinux, Rocky Linux).

Change another user’s password (root or sudo)

sudo passwd alice          # asks for the new password twice, not the old one
sudo passwd root           # change the root password

Set a password from a script

chpasswd reads user:password pairs, so it works without prompts:

echo 'alice:N3w-Strong-Pass!' | sudo chpasswd

The password ends up in your shell history this way, so clear it afterwards (history -d or history -c), or read it from a protected file instead.

Force a password change at next login

sudo passwd -e alice       # expire the password now
sudo chage -l alice        # "Last password change: password must be changed"

Check, lock and unlock a password

sudo passwd -S alice       # status: P = usable password, L or LK = locked
sudo passwd -l alice       # lock password logins
sudo passwd -u alice       # unlock

Locking only blocks password logins. The user can still log in with an SSH key, so remove their keys from ~/.ssh/authorized_keys too if you want to shut them out completely.

Choose a strong password

  • Use at least 12 characters, or better, a passphrase of several words.
  • Use a different password for every server and account; a password manager helps.
  • For SSH, key-based login is safer than any password.

Common problems

  • passwd: Authentication token manipulation error: usually a full or read-only disk, or damaged password files. See how to fix the authentication token manipulation error.
  • BAD PASSWORD: The password is shorter than 8 characters (or similar): the server’s password rules rejected it. Choose a longer, less predictable password.
  • Forgot the root password of your Ucartz VPS or server: open a support ticket and our team helps you reset it.

Need users to change their password at first login? See how to force a user to change their password at next login.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)