iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
/etc/passwd stores account details in seven colon-separated fields; /etc/shadow stores password and aging information in nine fields on systems using shadow passwords. The x commonly seen in /etc/passwd points to the shadow-file arrangement. A blank password, a locked password, an expired password, and an expired account are different states—and none alone describes every authentication route a system may allow.
What is the difference between /etc/passwd and /etc/shadow?
/etc/passwd is a text record of local user accounts. Its fields identify the account, numeric IDs, descriptive information, home directory, and login program. Programs need to read this information to map user IDs to names, so the usual permission model allows all users to read the file while reserving writes for the superuser. The Linux passwd(5) manual describes its role as recording user login accounts.
On a shadow-password setup, /etc/passwd commonly contains x in its password position, while the corresponding password verifier and password-aging values are kept in /etc/shadow. The shadow file has a more restrictive permission expectation: the Linux shadow(5) manual says it must not be readable by regular users if password security is to be maintained.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →These descriptions concern local account files. A host may instead use centrally managed identity, and applications, PAM configuration, and distribution choices affect actual authentication behavior. Check the host’s identity and login configuration before interpreting a local record as a complete picture of access.
#1 Best Overall
What do the seven fields in /etc/passwd mean?
A record follows this form:
name:password:UID:GID:GECOS:directory:shell
- Login name: The account name identifying this record.
- Password field: Often
xon a shadow-password system, indicating that the password verifier is stored in the matching/etc/shadowrecord. Other values have distinct meanings; see password markers below. - UID: The numeric user ID. UID
0is the privileged root identity. - GID: The numeric primary group ID. Additional group memberships are recorded in the group database, not in this field.
- GECOS/comment: Informational text, often a person’s name, that tools may display. Utilities using this field may expand an ampersand to the capitalized login name.
- Home directory: The directory used as the account’s home; login uses it to set
HOME. - Command interpreter: The login shell or initial program; login uses it to set
SHELL. The cited manual says an empty field defaults to/bin/sh.
What do the nine fields in /etc/shadow mean?
A shadow record follows this form:
login:password:last-change:min-age:max-age:warning:inactivity:account-expiration:reserved
- Login name: Identifies the account and should correspond to an account on the system.
- Password field: Holds the password verifier or a special value. A blank value may allow passwordless authentication, depending on the application; a leading
!locks the password. See the marker distinctions. - Last password change: The number of days since 1970-01-01 00:00:00 UTC.
0means the user must change the password at the next login. An empty field disables password-aging features. - Minimum password age: The number of days that must pass before the password can be changed. Empty or
0means no minimum wait. - Maximum password age: The number of days after which a password change is required. Once this period elapses, the password may still be accepted while the user is prompted to change it at the next login. Empty means no maximum age, warning period, or inactivity period. If this value is lower than the minimum age, the user cannot change the password.
- Warning period: The number of days before password expiration during which the user is warned. Empty or
0means no warning period. - Inactivity period: The number of days after password expiration during which the password remains accepted and the user must update it at the next login. After this period elapses, login is refused and the user must contact an administrator. Empty means no inactivity period is enforced.
- Account expiration date: A day count since 1970-01-01 after which the account cannot log in. Empty means the account does not expire. The manual cautions against using
0: it may be interpreted as no expiration or as 1970-01-01. - Reserved field: Reserved for future use.
What do x, a blank field, !, and * mean?
These markers do not all mean “disabled.” Their effects concern Unix-password authentication, not necessarily every method configured on the machine.
xin/etc/passwd: Commonly indicates that the password verifier is kept in the matching/etc/shadowrecord.- A blank password field: May allow passwordless login. Some applications reject blank passwords, so the field alone does not prove that passwordless access works—or that the account is disabled.
- A leading
!in the shadow password field: Locks the password; the characters after it preserve the value that was present before locking. A value that is not a validcrypt(3)result, such as!by itself or*, prevents Unix-password login. - Other authentication methods: A locked or non-crypt password value does not prove that all access is impossible. Other login methods may remain available, depending on the host’s applications and configuration.
How is password expiration different from account expiration?
Password aging governs the password: a maximum-age setting can trigger a password-change requirement, and the inactivity setting determines how long after password expiration the password remains accepted. Account expiration is a separate cutoff: once its date is reached, login to the account is prevented. Do not read an expired password as proof that the account itself has expired, or vice versa.
Quick Recap
Best Value
Rank #4
Rank #2
What can go wrong when reading or editing these files?
- Calling a blank password “disabled”: That is not a safe inference; a blank field can permit passwordless authentication, although an application may refuse it.
- Treating
!or*as proof that nobody can access the account: These values block Unix-password login, not necessarily other configured authentication paths. - Making shadow data readable to regular users: This defeats the documented protection model for password verifiers.
- Confusing a password-change requirement with an account cutoff: Password expiration and account expiration have different effects.
- Assuming local files are the entire identity system: A centrally managed identity source or host-specific authentication configuration may change what these records tell you about a login.
- Editing a record by hand without checking the system’s account-management method: Malformed records can damage account data. The
vipw(8)manual identifiesvipwfor editing/etc/passwdand/etc/shadow. Follow the distribution’s account-management documentation and the host’s identity configuration rather than assuming a procedure is universal.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

