On a Linux system using shadow passwords, what appears in the second (password) field of a normal user's line in /etc/passwd, and where does the password hash actually live?
LPIC-1 Exam 102-500, objective 110. Security easy
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct The hash itself; /etc/shadow only stores ageing information.
Wrong. The entire point of shadowing is to move the hash out of /etc/passwd, which must stay world-readable so that tools can map UIDs to names.
Correct An x; the hash is in /etc/shadow, which is not world-readable.
Correct. The x is a placeholder meaning 'look in the shadow file'. /etc/shadow is not world-readable — Debian-derived systems ship it as 0640 root:shadow, Red Hat-derived ones as 0000 root:root — so unprivileged users cannot read hashes to attack them offline.
Not correct An asterisk; the hash is in /etc/gshadow.
Wrong on both counts. An asterisk in the password field means no password will ever match, which is how many system accounts are disabled. /etc/gshadow holds group passwords and group administrators, not user hashes.
Not correct The field is left empty; the hash is in /etc/security/passwd.
Wrong, and hazardous. An empty password field means the account can be entered with no password at all. There is no /etc/security/passwd on Linux; /etc/security holds PAM module configuration such as limits.conf.
Why
/etc/passwd is world-readable and holds name, UID, GID, GECOS, home and shell. /etc/shadow is readable only by root (or a shadow group) and holds the hash plus the ageing fields chage manipulates. pwconv migrates an unshadowed system to shadow passwords and pwunconv reverses it; grpconv and grpunconv do the same for /etc/group and /etc/gshadow.
Where this comes from
- Cited
- LPI exam objective 110.2
- What it says
- Understand the role of shadow passwords and the files that hold them.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked