The /etc/shadow file in Linux Explained with Examples
A standalone Linux system saves usernames and passwords in separate files. It saves login information in the /etc/passwd file. It saves password information in the /etc/shadow file. It uses usernames to map entries of both files. In earlier versions, Linux used only one file to save both types of information. It saved all information in the /etc/passwd file. Later, due to security and scalability, it starts using the /etc/shadow to save all password-related information.
Security
System services use the /etc/passwd file to translate UID to username. Because of this, the /etc/passwd file must be world-readable. This requirement creates security risks. A hacker can obtain a copy of the /etc/passwd file and read passwords. Although passwords are encrypted, it is possible to read them using the following method.
The hacker can generate all possible passwords using a password-cracker tool, encrypt them using the same algorithm as the system, and compare them to the encrypted passwords saved in the /etc/passwd file.
Unlike the /etc/passwd file, the /etc/shadow file is not world-readable. To verify this, you can view the file permissions for both files.

As the above output shows, the /etc/shadow file has no file permission. Only the root or super user can read a file without permission.

Scalability
An /etc/passwd file entry allots only one field to save the password. Since each entry assigns only one field to save the password, it cannot save other password-related information in this file. An /etc/shadow file entry contains nine fields. All these fields are available for password and related information.

Each line in the /etc/shadow file represents an individual user account. It contains the following nine fields separated by colons (:).
- Username
- Encrypted password
- Date of last password change
- Minimum required days between password changes
- Maximum allowed days between password changes
- Number of days in advance to display password expiration message
- Number of days after password expiration to lock the account
- Account expiration date
- Reserve field

Username
Besides the password information, Linux saves all other login information in the /etc/passwd file. This field connects the /etc/shadow file and the /etc/passwd file. This field represents the login name and stores the same information in both files. When we add a new user account, Linux adds a new entry in both files. The first field of both entries contains the username in both files.

Encrypted password
The second field stores the password. It accepts the following values.
Empty field
An empty field means the account does not need a password. By default, this field never remains empty. If you do not create a password for an account, Linux uses a default value in this field of that account. The default values are !, !!, and *. If you want to keep this field empty or create a user account without a password, you can manually remove the default value from this field.
Let us take an example.
Add a new user account, but do not set a password. As mentioned earlier, if we do not set a password, Linux uses the default value in this field. Open the /etc/shadow file, find the user entry, remove the !! from this field, and save the file.

Log out from the root user or open a new virtual console and use this account to log in. You do not need a password for this account.

The exclamation sign (!)
The exclamation sign (!) represents a newly created account with no password or a blank password. When you add an account but do not set a password, Linux puts an exclamation sign (!) in this field. As mentioned above, if we keep this field empty, the user account needs only the username to log in. Anyone who knows the username can access the system without the password. It creates a security risk. To mitigate this security risk, Linux uses an exclamation sign (!) in this field. If this field has an exclamation sign (!), you cannot use the account to log in. This approach prevents unauthorized use of newly created user accounts or accounts without passwords.

Most Linux distros use a single exclamation sign (!) for it. A few distros, such as RHEL and Centos, use double exclamation signs (!!).
The asterisk sign (*)
The asterisk sign in this field represents a locked account. The default Linux installation creates many accounts for various services. To prevent unauthorized use of these accounts, Linux keeps them locked. We can not use these accounts for a standard login. Only the standard login process uses the /etc/shadow file for authentication. Other services (such as SSH, NFS, and FTP) use their database for authentication. If a service does not use this file for authentication, the value of this field cannot prevent it from logging.

Encrypted password
An encrypted password consists of the algorithm ID, salt, and user password. The passwd command sets an encrypted password in this field. It accepts a string as an argument. It adds a random salt to the given argument and encrypts the result using the system's default encryption algorithm. It adds the algorithm ID to the result as the prefix and saves the result in this field.

The following table lists the ID of most commonly used algorithms.
| $1$ | MD5 |
| $2a$ | Blowfish |
| $2y$ | Blowfish |
| $5$ | SHA-256 |
| $6$ | SHA-512 |
| $y$ | yescrypt |
The following table summarizes all valid values in this field.
| Value | Description | Can the user log in using this password? |
| None | The account does not need a password to log in. | Yes |
| ! or !! | The account does not have a password yet. | No |
| * | The account is locked for security reasons. | No |
| Encrypted password | The account has a password. | Yes |
Date of last password change
Linux keeps records of password changes. It uses this field to save the total number of days since the user changed the password. For days calculation, it uses 1 January 1970 as a starting day. For example, if a user changed his password on 05 July 2024, the number of days will be 19909.

In Linux, the date 1 January 1970 is called epoch. This date is used as the starting date or day to calculate the number of days or dates by several commands and configuration files.
You can use the following commands to convert the number of days into a date and vice versa.
#date
Without any options and arguments, the above command displays the current date.
#expr $(date +%s) / 86400
The above command calculates the number of days from 1 January 1970 til the current date.
#date -d "1970-01-01 [number of days] days"
The above command calculates the date from the given number of days. It starts counting from 1 January 1970.

Minimum required days between password changes
This field sets the minimum required days between two consecutive password changes. Once a password is changed, a user can not change his password until the days specified in this field have elapsed. If you set the value to zero (0), the user can change his password immediately.
Maximum allowed days between password changes
This field sets the maximum allowed days between password changes. Once a password is changed, a user must change his password again before the days specified in this field have elapsed. In other words, the days specified in this field are the maximum allowed days for a user to use a password. If this field is blank, a user can use his password as long as he wants. By default, there is a grace period of seven days. It will force the user to change his password when the days are set in this field and an extra seven days have passed.
Number of days in advance to display password expiration message
This field sets the days in advance for the display of the password expiration message. If the remaining days to change a password are less than or equal to the days specified in this field, the user will get a warning message to change his password. Warning message displays only on CLI prompt. It does not display on the GUI desktop.
Number of days after password expiration to lock the account
This field sets the days after password expiration to lock the account. If a user does not change his password within the maximum allowed days, it marks his password expired. It automatically locks a user account with the expired password once the days specified in this field have elapsed.
Account expiration date
This field sets an account expiration date. A user can not log in after the date specified in this field. If this field is blank, a user account will never expire.
Reserve field
The last field is available for future use.
The /etc/shadow file entry example
An entry in the /etc/shadow file looks like the following.
john:$6$iTEFbMTM$CXmxPwErbEef9RUBvf1zv8EgXQdaZg2eOd5uXyvt4sFzi6G4lIqavLilTQgniAHm3Czw/LoaGzoFzaMm.YwOl/:19909:0:90:14:::
The following table explains this entry.
| Field | Description |
| john | This is the username. |
| $6$iTEFbMTM$CXmxPwErbEef9 RUBvf1zv8EgXQdaZg2eOd5uXyvt4sFzi6G4lI qavLilTQgniAHm3Czw/LoaGzoFzaMm.YwOl/ | This is the encrypted password. |
| 19909 | John last changed his password on 05 July 2024. |
| 0 | If required, John can change his password immediately. |
| 90 | John can use this password till 10 October 2024. (90 + 7 grace days). |
| 14 | After 26 September 2024, he will get a warning message to change his password. |
| [bank field] | John's account will not be locked even if his password is expired. |
| [blank field] | John's account will never expire. |
| The reserve filed is omitted. |
This tutorial is part of the tutorial series 'Linux User and Group Management Explained with Examples'. Other parts of this series are the following.
Chapter 01 Difference between the root user and super (sudo) user
Chapter 02 Linux User Management Explained with Examples
Chapter 03 Linux Group Management Explained with Examples
Chapter 04 Password aging policy Explained with chage command
Chapter 05 The /etc/group File Explained
Chapter 06 The /etc/gshadow File Explained
Chapter 07 The /etc/passwd file in Linux Explained with Examples
Chapter 08 The /etc/shadow file in Linux Explained with Examples
Chapter 09 The useradd command Explained
Chapter 10 The gpasswd command Explained
Chapter 11 The chage command Examples and Usages
Conclusion
The /etc/shadow file saves passwords and related information for local user accounts. It saves passwords in an encrypted format. The login process uses this file to authenticate local user accounts.
Author Laxmi Goswami Updated on 2026-04-11