The Cryptographic Rotation Vector
The local user password on an Ubuntu server acts as the primary cryptographic gatekeeper. It not only grants access to the active terminal session but also mathematically authorizes privilege escalation via the `sudo` command. If a disgruntled employee departs the organization, or if you suspect your SSH keys or local password string have been compromised by a brute-force attack, you must immediately instruct the Linux kernel to execute a cryptographic rotation. This process shreds the legacy hash stored in the `/etc/shadow` registry and injects a newly generated authentication sequence.
How to Change Password in Ubuntu
The Ubuntu architecture utilizes the `passwd` utility to manage authentication strings. Because you are modifying core system security registries, the command’s behavior changes depending on whether you are rotating your own password or forcing a reset for another user.
1. Open your terminal application or connect to the server via SSH.
2. Scenario A: Changing Your Own Password
* If you are logged into your own account (e.g., `developer@server`) and wish to rotate your own credentials, you do not need root privileges.
* Type exactly:
passwd
* Press Enter.
* The kernel will prompt you to verify your identity: Current password: Type your existing password and press Enter.
* The kernel will then request the new cryptographic string: New password: Type your highly secure, new alphanumeric password. (Note: The terminal will remain completely blank as you type for security; no asterisks will appear). Press Enter.
* The kernel will demand verification: Retype new password: Type the exact new string again and press Enter.
* If the hashes match, the system outputs: `passwd: password updated successfully`.
3. Scenario B: Forcing a Password Reset for Another User (Admin Only)
* If you are the system administrator (`root` or acting via `sudo`) and need to mathematically lock out or reset the password for a different user (e.g., a user named `contractor`).
* Type exactly:
sudo passwd contractor
* Press Enter and supply your own `sudo` password to authorize the administrative override.
* Because you possess root privileges, the kernel will not ask for the user’s current password. It will immediately prompt you to inject the new string: New password:
* Type the new password, press Enter, verify it, and press Enter again.
4. The Force-Expiration Protocol (Optional):
* If you reset a user’s password to a temporary string (e.g., `TempPassword123`) and want to mathematically force them to choose their own secure password the very next time they log in.
* Type exactly:
sudo passwd -e contractor
* Press Enter. The kernel instantly expires the active hash, triggering a mandatory reset protocol upon their next successful SSH handshake.