How to Reset a Forgotten Root or User Password on Linux
Forgot the password for your own Linux machine, inherited a server nobody has the credentials for, or locked yourself out of root? If you can reach the machine’s console, you can reset any password. This guide covers the three standard methods and the distribution-specific details that make them fail.
A word on what this means for security: anyone with physical or console access can do exactly the same thing. That is why full-disk encryption matters, which the last section covers.
Before you start
- You need console access: a physical keyboard and screen, or a virtual console from your VPS provider, Proxmox, or virt-manager. SSH is not enough
- If the disk is LUKS-encrypted, you will still need the encryption passphrase at boot
- If you just need another user’s password reset and you have a working admin account, simply use
sudo passwd usernameand skip all of this
Method 1: Ubuntu and Debian recovery mode
The friendliest option, when it is available:
- Reboot and hold Shift (BIOS) or press Esc (UEFI) to show the GRUB menu
- Choose Advanced options for Ubuntu
- Select an entry ending in (recovery mode)
- From the recovery menu, choose root (Drop to root shell prompt)
Then:
mount -o remount,rw /
passwd alice # or just passwd for root
sync
reboot
On some systems the recovery mode root shell asks for the root password. Debian, for example, does this when a root password is set. In that case, use method 2.
Method 2: edit the kernel command line in GRUB
This works on almost every distribution.
- At the GRUB menu, highlight your normal entry and press e to edit it
- Find the line starting with
linux(orlinuxefi) - Add a parameter to the end of that line, depending on the distribution (below)
- Press Ctrl+X or F10 to boot
Debian, Ubuntu, Arch, and most others: init=/bin/bash
Append:
init=/bin/bash
The kernel starts a bash shell as PID 1 instead of your init system, as root, with no login. The root filesystem is usually mounted read-only, so:
mount -o remount,rw /
passwd alice
sync
exec /sbin/init # continue booting normally, or: reboot -f
A normal reboot does not work here because there is no init system running to handle it, hence exec /sbin/init or reboot -f.
Fedora, RHEL, Rocky, and Alma: rd.break
These distributions use rd.break, which stops in the initramfs before the real root is switched to:
rd.break
At the switch_root prompt:
mount -o remount,rw /sysroot
chroot /sysroot
passwd alice
touch /.autorelabel # important on SELinux systems, see below
exit
exit
The touch /.autorelabel line matters. Changing /etc/shadow from this shell can leave it with the wrong SELinux label, and then the login process is denied access to it and nobody can log in. The marker file triggers a full relabel on the next boot, which takes a few minutes. See our SELinux explainer for why labels matter.
Our guides to the GRUB bootloader, kernel command-line parameters, and initramfs explain what each of these steps is doing.
Method 3: a live USB
When you cannot edit GRUB, for example because it is password-protected, the menu is hidden and will not appear, or the system uses something else, boot from a live USB instead. Our bootable USB guide covers making one.
From the live session:
lsblk -f # find the root partition
sudo mount /dev/nvme0n1p2 /mnt # your root partition
# for LUKS: sudo cryptsetup open /dev/nvme0n1p3 root && sudo mount /dev/mapper/root /mnt
sudo chroot /mnt passwd alice
sudo umount /mnt
For Btrfs root subvolumes, mount the right subvolume, for example -o subvol=@. Our chroot rescue guide covers the full procedure, including bind-mounting /dev, /proc, and /sys for anything more involved than passwd.
Common problems
| Symptom | Cause | Fix |
|---|---|---|
passwd: Authentication token manipulation error | Root filesystem still read-only | mount -o remount,rw / |
| Login fails after reset (Fedora/RHEL) | SELinux label on /etc/shadow | Repeat and touch /.autorelabel |
The e key does nothing in GRUB | GRUB password set | Use a live USB |
| No GRUB menu appears | Menu hidden with a zero timeout | Hold Shift or tap Esc during boot |
| Keyboard layout wrong in the shell | Default US layout | Type the new password with that in mind, or set it temporarily with loadkeys |
Locking it down
If this was easy on your machine, it is easy for anyone who can touch it. In order of importance:
- Encrypt the disk with LUKS. Without the passphrase, none of these methods reach the data. This is the only measure that actually protects it; see LUKS disk encryption and, for convenience, TPM unlock
- Set a GRUB password so boot entries cannot be edited
- Set a firmware (UEFI) password and disable booting from external media
- Secure Boot to block unsigned bootloaders
And to avoid needing this guide again, keep passwords in a manager such as pass or KeePassXC, and make sure at least one account with sudo access is documented somewhere safe.
Frequently Asked Questions
Can I reset a Linux password without the old one?
Yes, if you have physical or console access. Booting with a modified kernel command line or from a live USB gives you a root shell without asking for a password, from which passwd can set a new one for any account. This is why physical access is treated as root access.
What is the easiest method on Ubuntu?
Recovery mode. Choose Advanced options for Ubuntu in the GRUB menu, select a recovery mode entry, and pick the root shell option. Remount the filesystem read-write with mount -o remount,rw /, then run passwd with the username.
Why does passwd fail with an authentication token manipulation error?
Almost always because the root filesystem is still mounted read-only. Run mount -o remount,rw / and try passwd again.
Why can I not log in after resetting the password on Fedora or RHEL?
SELinux labels. Editing /etc/shadow from the emergency shell can leave it with the wrong security label, and the login program is then denied access. Running touch /.autorelabel before rebooting makes the system relabel files on the next boot and fixes it.
Does this work if my disk is encrypted?
Only if you know the disk encryption passphrase, because you still have to unlock the disk at boot. Disk encryption is exactly what stops someone else from resetting your password with physical access, so if the passphrase is lost too, the data cannot be recovered.
How do I stop other people from doing this to my machine?
Encrypt the disk with LUKS, set a GRUB password so boot entries cannot be edited, set a firmware password, and disable booting from USB in the firmware. Disk encryption is the measure that actually protects the data; the others only slow an attacker down.