passwd: Authentication token manipulation error
passwd couldn’t update the password — the root filesystem is read-only, /etc/shadow has wrong permissions/attributes, or a PAM rule rejected it.
Seen on:
Linux
Meaning
Common in recovery mode (root mounted read-only), on systems where /etc/shadow was made immutable, or when the disk is full.
Common causes
- Root filesystem mounted read-only (recovery/single-user mode)
- /etc/shadow or /etc/passwd immutable (chattr +i) or wrong permissions
- Disk full
- PAM password policy/module failure
⚡ Quick fix
- Remount rw: mount -o remount,rw /
- Check lsattr /etc/shadow and permissions
- Free disk space
Detailed fix by platform
Linux
- bash
mount -o remount,rw / lsattr /etc/shadow /etc/passwd ls -l /etc/shadow # should be root:shadow 640 (Debian) or 000 (RHEL) passwd username
How to diagnose
- Mount — ro or rw?
- Attributes — lsattr flags
- Disk — df -h /
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Linux
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026