To change the root password on a Linux VPS, connect over SSH as root and run passwd. Type the new password twice; nothing appears on screen while you type. Before you close that session, open a second SSH session and log in with the new password to make sure it works.
The steps are the same on AlmaLinux, Rocky Linux, Ubuntu and Debian.
Before you start
- You need an open SSH session to the server. If you are not connected yet, follow How to Connect to Your Linux VPS with SSH.
- Prepare the new password first and keep it in a password manager. A good root password is at least 16 characters long and is not used anywhere else.
If you want the server to generate a random one, run:
openssl rand -base64 24
Change the root password
- Log in as root.
- Run
passwd. - Enter the new password at New password and again at Retype new password.
passwd
On Ubuntu and Debian a successful change ends with passwd: password updated successfully. On AlmaLinux and Rocky Linux the last line is passwd: all authentication tokens updated successfully.
Test before you log out
This is the step that prevents lockouts. Keep your current session open and start a second terminal:
ssh root@203.0.113.10 -p 22
Log in with the new password. If it works, you can close both sessions. If it does not, you still have the first session open: run passwd again and repeat the test.
Change another user’s password
As root, add the username after the command:
passwd deploy
If you are logged in as a normal user with sudo rights, use sudo. The first password you type is your own, for sudo; then you set the new one:
sudo passwd deploy
sudo passwd root
A normal user can change their own password with plain passwd. They will be asked for the current password first.
What the common messages mean
BAD PASSWORD: The password is shorter than 8 characters (or *is a palindrome*, *fails the dictionary check*). The password quality check is warning you. When you run the command as root the change still goes through, but choose a stronger password anyway.
passwd: Authentication token manipulation error. The password files could not be written. This is usually because the disk is full or the root filesystem is mounted read-only. Check free space with:
df -h /
passwd: Only root can specify a user name. You ran passwd username without root rights. Put sudo in front of it.
Does changing the password affect SSH keys?
No. If you log in with an SSH key, the key keeps working after the password change, because SSH checks the key, not the password. This also means that a password change alone does not lock out someone who has added their own key. To review which keys can log in as root, run:
cat ~/.ssh/authorized_keys
Remove any line you don’t recognise.
Changing a password without the interactive prompt
Scripts sometimes need to set a password in one line. The chpasswd tool reads user:password pairs:
echo 'deploy:N3w-Long-Passw0rd-Here' | chpasswd
The password ends up in your shell history this way. Use it in automation only, and clear the history entry afterwards with history -d followed by the line number.
Lost the root password?
The password can’t be recovered or read from inside the server, because Linux only stores a one-way hash of it. If you still have a working SSH key or a sudo user, log in that way and run sudo passwd root. If you have no way in, open a ticket from our contact page with the server IP, and we will help you regain access.
Frequently asked questions
Why can’t I see the password while typing?
Linux hides password input completely so that nobody watching can see its length. Type it and press Enter.
Do I need to restart the server or SSH after changing the password?
No. The new password works immediately, and open sessions stay connected.
How do I check when a password was last changed?
Run chage -l root. The line *Last password change* shows the date.
Is the root password the same as the Client Area password?
No. The Client Area login is separate. Changing one does not change the other.
