## Set and manage user passwords and account locking

# Change your own password
passwd

# Change another user's password
sudo passwd merab

# Change the root password
sudo passwd root

# Show the status of an account
sudo passwd -S merab

# Status of every account
sudo passwd -Sa

# Lock an account's password, so password login fails
sudo passwd -l merab

# Unlock it again
sudo passwd -u merab

# Delete the password, leaving the account passwordless (dangerous)
sudo passwd -d merab

# Force a password change at the next login
sudo passwd -e merab

# Minimum days between password changes
sudo passwd -n 1 merab

# Maximum days a password stays valid
sudo passwd -x 90 merab

# Warn 7 days before expiry
sudo passwd -w 7 merab

# Lock the account after 14 inactive days past expiry
sudo passwd -i 14 merab

# Set a password non-interactively from a script
echo 'merab:newpassword' | sudo chpasswd

# Set several passwords at once from a file
sudo chpasswd < users-and-passwords.txt

# Feed a pre-hashed password
echo "merab:$(openssl passwd -6 'newpassword')" | sudo chpasswd -e

# Generate a SHA-512 hash to store
openssl passwd -6 'newpassword'

# Generate a hash with mkpasswd
mkpasswd -m sha-512

# Generate a random password
openssl rand -base64 18

# Random password from urandom
tr -cd '[:alnum:]' < /dev/urandom | head -c 20; echo

# Show password ageing in a readable form
sudo chage -l merab

# Set the maximum age with chage
sudo chage -M 90 merab

# Expire an account on a date
sudo chage -E 2026-12-31 contractor

# Force a change at next login, with chage
sudo chage -d 0 merab

# Never expire
sudo chage -M -1 merab

# Where the hashes actually live
sudo grep merab /etc/shadow

# Which hashing algorithm is in use ($6$ is SHA-512)
sudo awk -F: '$1=="merab" {print substr($2,1,3)}' /etc/shadow

# Find accounts with no password set
sudo awk -F: '$2 == "" {print $1}' /etc/shadow

# Find locked accounts
sudo awk -F: '$2 ~ /^!/ {print $1}' /etc/shadow

# Check the password file for inconsistencies
sudo pwck

# Check the group file too
sudo grpck

# Password policy set by PAM
grep -v '^#' /etc/security/pwquality.conf

# Prefer SSH keys over passwords for remote logins
ssh-keygen -t ed25519 -C "merab@laptop"
