The Security Rotation Vector
In a standard Linux server environment, rotating user passwords is a fundamental security requirement. If an employee departs the organization, or if you suspect a specific user account has been compromised, you must immediately overwrite their authentication credentials. Because Ubuntu servers rarely utilize a graphical desktop environment, you cannot rely on a control panel interface; you must interface directly with the kernel’s underlying authentication database via the command line.
How to Change a User Password
The Ubuntu operating system utilizes a highly specific command engineered exclusively for modifying the cryptographic hashes stored in the hidden `/etc/shadow` file.
1. Open your terminal application or connect to your server via SSH.
2. Changing Your Own Password: If you are simply logged in as standard user `johndoe` and wish to update your own credential, type the following command and press Enter:
passwd
The system will first demand your current password to verify your identity, and then prompt you twice for the new password.
3. Changing Another User’s Password (Admin Only): If you are the system administrator and need to forcefully overwrite the password of a different user (e.g., a user named `sarah`), you must invoke superuser privileges. Execute the following command:
sudo passwd sarah
4. The Blind Entry Protocol: The terminal will prompt you to `Enter new UNIX password:`. As you begin typing the new password, absolutely nothing will appear on the screen. There will be no asterisks, dots, or cursor movement. This is an intentional Linux security feature designed to prevent shoulder-surfing. Type the password confidently and press Enter.
5. The system will ask you to `Retype new UNIX password:`. Type it blindly again and press Enter.
If the two entries match, the kernel will output `passwd: password updated successfully`. The new credential is instantaneously active.