The Credential Rotation Vector
Maintaining tight security on a Linux server requires frequent credential rotation. If an administrator leaves your organization, or if you suspect your SSH keys have been compromised, you must immediately change the passwords for all active accounts on the system. Unlike desktop operating systems that provide elaborate graphical control panels, Ubuntu Server relies on a single, highly focused command-line utility to interact with the system’s encrypted credential database (`/etc/shadow`).
How to Change Your User Password
You must invoke the passwd utility to securely overwrite your existing authentication token.
1. Open your terminal application or connect to your server via SSH.
2. To change your own password: Simply execute the command with no additional flags:
passwd
3. The system will first prompt you to enter your Current password. (Note: When typing passwords in a Linux terminal, the cursor will not move and no asterisks will appear. This is intentional. Type carefully and press Enter).
4. The system will then prompt you to enter the New password.
5. Finally, it will ask you to Retype new password to confirm there were no typographical errors.
6. To change another user’s password (Administrators Only): If you possess sudo privileges and need to force a reset on a subordinate account (e.g., an account named `johndoe`), you must prepend the command with sudo and append the target username:
sudo passwd johndoe
Because you are invoking superuser privileges, the system will entirely bypass the requirement to know John Doe’s current password and immediately demand the new authentication string.