On a Linux system using shadow passwords, what appears in the second (password) field of a normal user's line in /etc/passwd, and where does the password hash actually live?

LPIC-1 Exam 102-500, objective 110. Security easy

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct The hash itself; /etc/shadow only stores ageing information.

Wrong. The entire point of shadowing is to move the hash out of /etc/passwd, which must stay world-readable so that tools can map UIDs to names.

Correct An x; the hash is in /etc/shadow, which is not world-readable.

Correct. The x is a placeholder meaning 'look in the shadow file'. /etc/shadow is not world-readable — Debian-derived systems ship it as 0640 root:shadow, Red Hat-derived ones as 0000 root:root — so unprivileged users cannot read hashes to attack them offline.

Not correct An asterisk; the hash is in /etc/gshadow.

Wrong on both counts. An asterisk in the password field means no password will ever match, which is how many system accounts are disabled. /etc/gshadow holds group passwords and group administrators, not user hashes.

Not correct The field is left empty; the hash is in /etc/security/passwd.

Wrong, and hazardous. An empty password field means the account can be entered with no password at all. There is no /etc/security/passwd on Linux; /etc/security holds PAM module configuration such as limits.conf.

Why

/etc/passwd is world-readable and holds name, UID, GID, GECOS, home and shell. /etc/shadow is readable only by root (or a shadow group) and holds the hash plus the ageing fields chage manipulates. pwconv migrates an unshadowed system to shadow passwords and pwunconv reverses it; grpconv and grpunconv do the same for /etc/group and /etc/gshadow.

Where this comes from

Cited
LPI exam objective 110.2
What it says
Understand the role of shadow passwords and the files that hold them.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500