Authentication token manipulation error 🐧 Linux

passwd: Authentication token manipulation error

passwd couldn’t update the password — the root filesystem is read-only, /etc/shadow has wrong permissions/attributes, or a PAM rule rejected it.

Seen on: Linux

Meaning

Common in recovery mode (root mounted read-only), on systems where /etc/shadow was made immutable, or when the disk is full.

Common causes

  • Root filesystem mounted read-only (recovery/single-user mode)
  • /etc/shadow or /etc/passwd immutable (chattr +i) or wrong permissions
  • Disk full
  • PAM password policy/module failure

⚡ Quick fix

  1. Remount rw: mount -o remount,rw /
  2. Check lsattr /etc/shadow and permissions
  3. Free disk space

Detailed fix by platform

Linux

  1. bash
    mount -o remount,rw /
    lsattr /etc/shadow /etc/passwd
    ls -l /etc/shadow   # should be root:shadow 640 (Debian) or 000 (RHEL)
    passwd username

How to diagnose

  1. Mount — ro or rw?
  2. Attributes — lsattr flags
  3. Disk — df -h /

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.