Error report when changing password: passwd: Authentication token manipulation error
When changing a user's password, the error message is as follows:
Passwd: Authentication token manipulation error
Solution.
Check whether the following configurations of / etc/pam.d/passwd and / etc/pam.d/system-auth exist:
1 、 cat / etc/pam.d/passwd
#% PAM-1.0
Auth required pam_stack.so service=system-auth
Account required pam_stack.so service=system-auth
Password required pam_stack.so service=system-auth
Password required pam_cracklib.so dcredit=-1 ucredit=-1 ocredit=-1 lcredit=-1 minlen=6
Password required pam_unix.so use_authtok nullok md5
Password required pam_unix.so remember=5 use_authtok
Some of the last three lines are not supported by the old system, and the setting will also lead to the error report above.
2 、 cat / etc/pam.d/system-auth
#% PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
Auth required / lib/security/$ISA/pam_env.so
Auth sufficient / lib/security/$ISA/pam_unix.so likeauth nullok
Auth required / lib/security/$ISA/pam_deny.so
Account required / lib/security/$ISA/pam_unix.so
Account sufficient / lib/security/$ISA/pam_succeed_if.so uid < 100quiet
Account required / lib/security/$ISA/pam_permit.so
Password requisite / lib/security/$ISA/pam_cracklib.so retry=3
Password sufficient / lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
Password required / lib/security/$ISA/pam_deny.so
Session required / lib/security/$ISA/pam_limits.so
Session required / lib/security/$ISA/pam_unix.so
3. You can also modify the password string of shadow file directly.
Method 1)
Perl-e'print crypt ("password", "\ $1\ $2BDxrkQc\ $"), "\ n"'
Note: the 2BDxrkQc here is the content of salt ($3) in shadow. If you want to generate salt randomly, you can use method 2.
Method 2)
Echo "password" | openssl passwd-1-salt $(< / dev/urandom tr-dc'[: alnum:]'| head-c 32)-stdin