How to Reset a Forgotten Root or User Password on Linux

How to Reset a Forgotten Root or User Password on Linux

Forgot the password for your own Linux machine, inherited a server nobody has the credentials for, or locked yourself out of root? If you can reach the machine’s console, you can reset any password. This guide covers the three standard methods and the distribution-specific details that make them fail.

A word on what this means for security: anyone with physical or console access can do exactly the same thing. That is why full-disk encryption matters, which the last section covers.

Before you start

  • You need console access: a physical keyboard and screen, or a virtual console from your VPS provider, Proxmox, or virt-manager. SSH is not enough
  • If the disk is LUKS-encrypted, you will still need the encryption passphrase at boot
  • If you just need another user’s password reset and you have a working admin account, simply use sudo passwd username and skip all of this

Method 1: Ubuntu and Debian recovery mode

The friendliest option, when it is available:

  1. Reboot and hold Shift (BIOS) or press Esc (UEFI) to show the GRUB menu
  2. Choose Advanced options for Ubuntu
  3. Select an entry ending in (recovery mode)
  4. From the recovery menu, choose root (Drop to root shell prompt)

Then:

mount -o remount,rw /
passwd alice          # or just passwd for root
sync
reboot

On some systems the recovery mode root shell asks for the root password. Debian, for example, does this when a root password is set. In that case, use method 2.

Method 2: edit the kernel command line in GRUB

This works on almost every distribution.

  1. At the GRUB menu, highlight your normal entry and press e to edit it
  2. Find the line starting with linux (or linuxefi)
  3. Add a parameter to the end of that line, depending on the distribution (below)
  4. Press Ctrl+X or F10 to boot

Debian, Ubuntu, Arch, and most others: init=/bin/bash

Append:

init=/bin/bash

The kernel starts a bash shell as PID 1 instead of your init system, as root, with no login. The root filesystem is usually mounted read-only, so:

mount -o remount,rw /
passwd alice
sync
exec /sbin/init       # continue booting normally, or: reboot -f

A normal reboot does not work here because there is no init system running to handle it, hence exec /sbin/init or reboot -f.

Fedora, RHEL, Rocky, and Alma: rd.break

These distributions use rd.break, which stops in the initramfs before the real root is switched to:

rd.break

At the switch_root prompt:

mount -o remount,rw /sysroot
chroot /sysroot
passwd alice
touch /.autorelabel   # important on SELinux systems, see below
exit
exit

The touch /.autorelabel line matters. Changing /etc/shadow from this shell can leave it with the wrong SELinux label, and then the login process is denied access to it and nobody can log in. The marker file triggers a full relabel on the next boot, which takes a few minutes. See our SELinux explainer for why labels matter.

Our guides to the GRUB bootloader, kernel command-line parameters, and initramfs explain what each of these steps is doing.

Method 3: a live USB

When you cannot edit GRUB, for example because it is password-protected, the menu is hidden and will not appear, or the system uses something else, boot from a live USB instead. Our bootable USB guide covers making one.

From the live session:

lsblk -f                              # find the root partition
sudo mount /dev/nvme0n1p2 /mnt        # your root partition
# for LUKS: sudo cryptsetup open /dev/nvme0n1p3 root && sudo mount /dev/mapper/root /mnt
sudo chroot /mnt passwd alice
sudo umount /mnt

For Btrfs root subvolumes, mount the right subvolume, for example -o subvol=@. Our chroot rescue guide covers the full procedure, including bind-mounting /dev, /proc, and /sys for anything more involved than passwd.

Common problems

SymptomCauseFix
passwd: Authentication token manipulation errorRoot filesystem still read-onlymount -o remount,rw /
Login fails after reset (Fedora/RHEL)SELinux label on /etc/shadowRepeat and touch /.autorelabel
The e key does nothing in GRUBGRUB password setUse a live USB
No GRUB menu appearsMenu hidden with a zero timeoutHold Shift or tap Esc during boot
Keyboard layout wrong in the shellDefault US layoutType the new password with that in mind, or set it temporarily with loadkeys

Locking it down

If this was easy on your machine, it is easy for anyone who can touch it. In order of importance:

  1. Encrypt the disk with LUKS. Without the passphrase, none of these methods reach the data. This is the only measure that actually protects it; see LUKS disk encryption and, for convenience, TPM unlock
  2. Set a GRUB password so boot entries cannot be edited
  3. Set a firmware (UEFI) password and disable booting from external media
  4. Secure Boot to block unsigned bootloaders

And to avoid needing this guide again, keep passwords in a manager such as pass or KeePassXC, and make sure at least one account with sudo access is documented somewhere safe.

Frequently Asked Questions

Can I reset a Linux password without the old one?

Yes, if you have physical or console access. Booting with a modified kernel command line or from a live USB gives you a root shell without asking for a password, from which passwd can set a new one for any account. This is why physical access is treated as root access.

What is the easiest method on Ubuntu?

Recovery mode. Choose Advanced options for Ubuntu in the GRUB menu, select a recovery mode entry, and pick the root shell option. Remount the filesystem read-write with mount -o remount,rw /, then run passwd with the username.

Why does passwd fail with an authentication token manipulation error?

Almost always because the root filesystem is still mounted read-only. Run mount -o remount,rw / and try passwd again.

Why can I not log in after resetting the password on Fedora or RHEL?

SELinux labels. Editing /etc/shadow from the emergency shell can leave it with the wrong security label, and the login program is then denied access. Running touch /.autorelabel before rebooting makes the system relabel files on the next boot and fixes it.

Does this work if my disk is encrypted?

Only if you know the disk encryption passphrase, because you still have to unlock the disk at boot. Disk encryption is exactly what stops someone else from resetting your password with physical access, so if the passphrase is lost too, the data cannot be recovered.

How do I stop other people from doing this to my machine?

Encrypt the disk with LUKS, set a GRUB password so boot entries cannot be edited, set a firmware password, and disable booting from USB in the firmware. Disk encryption is the measure that actually protects the data; the others only slow an attacker down.