Linux

Where Are Linux User Accounts and Passwords Stored?

Linux keeps user accounts in /etc/passwd and password hashes in /etc/shadow. What each file holds and how to edit them safely.

Last updated

Every local user account on a Linux system is a line in /etc/passwd: username, user ID, group ID, home directory and login shell, all world-readable. Password hashes are deliberately absent. They live one file over in /etc/shadow, readable only by root, alongside expiry and aging fields.

Group membership completes the trio in /etc/group, with group passwords (rarely used) in /etc/gshadow. These four files predate most Linux distributions and have barely changed in decades, so this page will not go stale. Never edit them directly; vipw and vigr exist because a stray typo here locks out the whole machine.

Where Linux users stores this, by platform

Linux
/etc/passwd

One line per account: name, UID, GID, home dir, shell. World-readable by design. Hashes are in /etc/shadow (root only), groups in /etc/group, group admin in /etc/gshadow. Edit with vipw and vigr, verify with pwck and grpck. Same paths on every mainstream distribution.

Frequently asked questions

why are there two files for users instead of one

History and permissions. Password hashes once sat in world-readable passwd, letting anyone run cracking attempts offline. Shadow moved them into a root-only file in the 1990s. Modern systems keep the split even though the original attack is dated; the plumbing assumes it.

how do i safely edit passwd or shadow

Do not edit them in a normal text editor. Use vipw for passwd and group, and vigr for group and gshadow; they lock the files and run syntax checks on save. Run pwck and grpck afterward to verify consistency. A typo in passwd can lock out every login, so the guardrails matter.

where are password hashes stored on linux

In /etc/shadow's second field. A locked or passwordless system account shows ! or * there instead of a hash, which is normal for service users. Real user entries show a long hash string. Only root can read the file, so use sudo to inspect it.

Notice an outdated path? Let us know.