22 January 2008

Format of /etc/shadow file

/etc/shadow file stores actual password in encrypted format and password aging information for user's account.

test1:$1$zT1YmCtj$NL67d.yN/gL9eVgyimhL./:13899:20:30:7:::

All fields are separated by a colon(:) symbol
  1. User name : It is your login name
  2. Password: It your encrypted password. The password should be minimum 6-8 characters long including special characters/digits
  3. Last password change (lastchanged): Days since Jan 1, 1970 that password was last changed
  4. Minimum: The minimum number of days required between password changes i.e. the number of days left before the user is allowed to change his/her password
  5. Maximum: The maximum number of days the password is valid (after that user is forced to change his/her password)
  6. Warn : The number of days before password is to expire that user is warned that his/her password must be changed
  7. Inactive : The number of days after password expires that account is disabled
  8. Expire : Days since Jan 1, 1970 that account is disabled i.e. an absolute date specifying when the login may no longer be used
The last 6 fields provides password aging and account lockout features.Password field must be filled. The encrypted password consists of 13 to 24 characters from the 64 character alphabet a through z, A through Z, 0 through 9, \. and /. Optionally it can start with a “$” character. This means the encrypted password was generated using another (not DES) algorithm. For example if it starts with “$1$” it means the MD5-based algorithm was used.

Output of chage command:
# chage -l test1
Minimum: 20
Maximum: 30
Warning: 7
Inactive: -1
Last Change: Jan 21, 2008
Password Expires: Feb 20, 2008
Password Inactive: Never
Account Expires: Never



No comments: