Q: What does the `/etc/shadow` file contain, and why is it separated from `/etc/passwd`?
/etc/passwd contains user account information (username, UID, GID, home directory, shell) and historically stored password hashes. Howeve...
🛠️ Production Runbook & Step-by-Step Resolution
Initial Diagnostics & Root Cause Analysis
/etc/passwd contains user account information (username, UID, GID, home directory, shell) and historically stored password hashes. However, /etc/passwd must be world-readable because many programs need to map UIDs to usernames.
- Username
- Hashed password (using algorithms like SHA-512, prefixed with
$6$) - Date of last password change (in days since epoch)
- Minimum days between password changes
Remediation & Permanent Safeguards
/etc/shadow was introduced to separate the sensitive password hashes into a file that is readable only by root (permissions 640 or 600). This prevents unprivileged users from reading hashed passwords and attempting offline brute-force attacks. Each line in /etc/shadow contains: To check password aging for a user: chage -l username. To force a password change on next login: chage -d 0 username.
- Maximum password age
- Warning period before expiry
- Account expiration date
- Username
- Hashed password (using algorithms like SHA-512, prefixed with $6$)
- Date of last password change (in days since epoch)