#Bash 的 chage 命令
chage [OPTION] USER
功能
更改用户密码的有效期信息。
类型
可执行文件(/usr/bin/chage),属于 passwd。
参数
OPTION选项:-d,--lastday LAST_DAY- 设置上次更改密码的日期(可以采用 YYYY-MM-DD 格式或 1970 年 1 月 1 日以来的天数);设为 0 时下次登录必须更改密码-E,--expiredate EXPIRE_DATE- 设置账户的过期时间(可以采用 YYYY-MM-DD 格式或 1970 年 1 月 1 日以来的天数);设为 -1 表示不会过期-h,--help- 查看帮助-i,--iso8601- 使用 YYYY-MM-DD 格式的日期-I,--inactive INACTIVE- 设置账户的过期后经过多少天后锁定该账户;设为 -1 表示不会锁定-l,--list- 列出账户信息-m,--mindays MIN_DAYS- 设置两次密码更改之间最小间隔天数-M,--maxdays MAX_DAYS- 设置两次密码更改之间最大间隔天数;LAST_DAY+MAX_DAYS小于当前日期时,必须修改密码-R,--root CHROOT_DIR- 更改命令执行时的根路径;CHROOT_DIR必须是绝对路径,参考chroot-P,--prefix PREFIX_DIR- 使用PREFIX_DIR目录前缀下的配置文件(${PREFIX_DIR}/etc/passwd,${PREFIX_DIR}/etc/shadow等)-W,--warndays WARN_DAYS- 设置密码过期前提醒用户的天数
USER- 要操作的用户
#示例
查看信息
$ chage --list primers
Last password change : Jul 21, 2026
Password expires : never
Password inactive : never
Account expires : never
Minimum number of days between password change : 0
Maximum number of days between password change : 99999
Number of days of warning before password expires : 7
修改信息
$ sudo chage -d 2026-07-23 primers # 密更改码的日期修改为 2026-07-23
$ sudo chage -E 2027-07-23 primers # 账户过期日期修改为 2027-07-23
$ sudo chage -I 7 primers # 账户过期后 7 天锁定
$ sudo chage -M 30 primers # 密码有效期为 30 天
$ chage --list primers # 查看状态
Last password change : Jul 23, 2026
Password expires : Aug 22, 2026
Password inactive : Aug 29, 2026
Account expires : Jul 23, 2027
Minimum number of days between password change : 0
Maximum number of days between password change : 30
#推荐阅读
#手册
CHAGE(1) User Commands CHAGE(1)
NAME
chage - change user password expiry information
SYNOPSIS
chage [options] LOGIN
DESCRIPTION
The chage command changes the number of days between password changes
and the date of the last password change. This information is used by
the system to determine when a user must change their password.
OPTIONS
The options which apply to the chage command are:
-d, --lastday LAST_DAY
Set the number of days since January 1st, 1970 when the password was
last changed. The date may also be expressed in the format
YYYY-MM-DD (or the format more commonly used in your area). If the
LAST_DAY is set to 0 the user is forced to change his password on
the next log on.
-E, --expiredate EXPIRE_DATE
Set the date or number of days since January 1, 1970 on which the
user's account will no longer be accessible. The date may also be
expressed in the format YYYY-MM-DD (or the format more commonly used
in your area). A user whose account is locked must contact the
system administrator before being able to use the system again.
For example the following can be used to set an account to expire in
180 days:
chage -E $(date -d +180days +%Y-%m-%d)
Passing the number -1 as the EXPIRE_DATE will remove an account
expiration date.
-h, --help
Display help message and exit.
-i, --iso8601
When printing dates, use YYYY-MM-DD format.
-I, --inactive INACTIVE
Set the number of days of inactivity after a password has expired
before the account is locked. The INACTIVE option is the number of
days of inactivity. A user whose account is locked must contact the
system administrator before being able to use the system again.
Passing the number -1 as the INACTIVE will remove an account's
inactivity.
-l, --list
Show account aging information.
-m, --mindays MIN_DAYS
Set the minimum number of days between password changes to MIN_DAYS.
A value of zero for this field indicates that the user may change
their password at any time.
-M, --maxdays MAX_DAYS
Set the maximum number of days during which a password is valid.
When MAX_DAYS plus LAST_DAY is less than the current day, the user
will be required to change their password before being able to use
their account. This occurrence can be planned for in advance by use
of the -W option, which provides the user with advance warning.
Passing the number -1 as MAX_DAYS will remove checking a password's
validity.
-R, --root CHROOT_DIR
Apply changes in the CHROOT_DIR directory and use the configuration
files from the CHROOT_DIR directory. Only absolute paths are
supported.
-P, --prefix PREFIX_DIR
Apply changes to configuration files under the root filesystem found
under the directory PREFIX_DIR. This option does not chroot and is
intended for preparing a cross-compilation target. Some limitations:
NIS and LDAP users/groups are not verified. No SELINUX support.
-W, --warndays WARN_DAYS
Set the number of days of warning before a password change is
required. The WARN_DAYS option is the number of days prior to the
password expiring that a user will be warned their password is about
to expire.
If none of the options are selected, chage operates in an interactive
fashion, prompting the user with the current values for all of the
fields. Enter the new value to change the field, or leave the line blank
to use the current value. The current value is displayed between a pair
of [ ] marks.
NOTE
The chage program requires a shadow password file to be available.
The chage program will report only the information from the shadow
password file. This implies that configuration from other sources (e.g.
LDAP or empty password hash field from the passwd file) that affect the
user's login will not be shown in the chage output.
The chage program will also not report any inconsistency between the
shadow and passwd files (e.g. missing x in the passwd file). The pwck
can be used to check for this kind of inconsistencies.
The chage command is restricted to the root user, except for the -l
option, which may be used by an unprivileged user to determine when
their password or account is due to expire.
CONFIGURATION
The following configuration variables in /etc/login.defs change the
behavior of this tool:
FILES
/etc/passwd
User account information.
/etc/shadow
Secure user account information.
EXIT VALUES
The chage command exits with the following values:
0
success
1
permission denied
2
invalid command syntax
15
can't find the shadow password file
SEE ALSO
passwd(5), shadow(5).
shadow-utils 4.17.4 02/02/2026 CHAGE(1)