You cannot read a user's actual password in Linux, but you can check if one is set
Linux stores passwords in a way that makes them unreadable — even to you, even if you are the system administrator. What you can do is check whether a password exists, whether it is locked, whether it has expired, and when it was last changed. This information lives in two files: /etc/passwd (which is readable by everyone) and /etc/shadow (which only root can read).
The method you use depends on what you actually need to know. If you are troubleshooting a login problem, you are looking for different information than if you are auditing which accounts have no password set at all. This guide covers the most common checks and what each one tells you.
Key Takeaways
- The passwd command with the -S flag shows whether a user has a password set, whether it is locked, and when it expires.
- The /etc/shadow file contains the actual password hash, but you must be root to read it, and the hash itself cannot be reversed to find the original password.
- An x in the password field of /etc/passwd means the password is stored in /etc/shadow (the normal setup); an empty field means no password is set.
- A ! or !! at the start of the hash in /etc/shadow means the account is locked and cannot be used to log in.
Check password status with the passwd command
The fastest way to see whether a user has a password and whether it is locked is to use passwd -S as root. Open a terminal and type:
sudo passwd -S username
Replace username with the actual username. The output will look something like this:
john L 01/15/2024 0 99999 7 -1
The letters and numbers mean: L = locked, P = password set, NP = no password. The dates that follow show when the password was last changed and when it will expire. If you see P, the user has a password. If you see L, the account is locked and cannot log in even with the correct password. If you see NP, no password is set at all.
Read the /etc/shadow file directly
The /etc/shadow file holds the actual password hashes. You must be root to read it. Type:
sudo cat /etc/shadow | grep username
Replace username with the account you want to check. The output will show a line like:
john:$6$abcd1234efgh5678$xyz...:19345:0:99999:7:::
The second field (between the first and second colons) is the password hash. If it starts with ! or !!, the account is locked. If it is empty or shows just *, no password is set. If it shows a long string starting with $1$, $2$, $5$, or $6$, a password is set and the account is active. The hash itself cannot be reversed — it is a one-way encryption.
Check /etc/passwd for the password field
The /etc/passwd file is readable by all users and shows basic account information. Type:
cat /etc/passwd | grep username
You will see a line like:
john:x:1000:1000:John Doe:/home/john:/bin/bash
The second field (between the first and second colons) is what matters. An x means the password is stored in /etc/shadow — this is the normal setup on modern Linux systems. An empty field means no password is set. You will almost never see an actual password hash here; if you do, the system is misconfigured.
Understand what the password hash tells you
A password hash is a scrambled version of the password that cannot be unscrambled. Even if you have the hash, you cannot read the original password. What you can do is run a password-cracking tool that guesses thousands of passwords, hashes each guess, and compares it to the stored hash. If a match is found, the guess was correct. This is why strong passwords matter — weak ones are cracked quickly.
The prefix of the hash (the $6$ part) tells you which hashing algorithm was used. $1$ is MD5 (old and weak). $5$ is SHA-256. $6$ is SHA-512 (current standard). Newer systems may show $2a$, $2b$, or $2y$ for bcrypt, which is even stronger.
Check when a password was last changed
To see the password age information, use passwd -S again or read /etc/shadow directly. The third field in /etc/shadow shows the number of days since January 1, 1970 when the password was last changed. You can convert this to a readable date, but passwd -S does that for you automatically.
If the password age field is empty or shows 0, the user has never set a password or the password was set before the system started tracking this information. If you see a recent date, the password was changed recently. Some organizations require password changes every 90 days; the expiration fields in /etc/shadow enforce that rule.
Identify accounts with no password set
To find all user accounts that have no password, run:
sudo awk -F: '($2 == "" || $2 == "!" || $2 == "!!") {print $1}' /etc/shadow
This searches /etc/shadow for accounts where the password field is empty or locked. Any account with an empty password field is a security risk — anyone can log in as that user without entering a password. System accounts (like root, bin, daemon) often have locked passwords by design, which is correct. Regular user accounts should never have empty passwords.
Frequently Asked Questions
Can I see what password a user typed?
No. Linux hashes passwords one-way, so the original password is never stored. Even root cannot read the actual password. If a user forgets their password, you must reset it to a new one using sudo passwd username.
What does it mean if passwd -S shows NP?
NP means "no password." The account exists but has no password set, so anyone can log in as that user without entering anything. This is a security problem for regular user accounts. System accounts often have NP by design.
How do I lock a user account without deleting it?
Use sudo passwd -l username. This adds ! to the start of the password hash, preventing login. The account and its files remain intact. Use sudo passwd -u username to unlock it.
What if the password hash starts with $2a$ instead of $6$?
That account uses bcrypt hashing, which is stronger than SHA-512. It is more resistant to cracking. This is normal and secure; no action is needed.
Can I see password expiration dates?
Yes. Run sudo passwd -S username and look at the dates shown. The last field before the dashes shows how many days until expiration (or -1 if it never expires). You can also read the raw numbers in /etc/shadow and convert them to dates if needed.