# User pass change (break the glass)

On boot, stop the GRUB loader pressing `E`

[![image.png](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/scaled-1680-/eNqMYTHIHpqTrZpv-image.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/eNqMYTHIHpqTrZpv-image.png)

add to the end of the line, where linux is declared

[![image.png](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/scaled-1680-/tVog6mAFbjhbUDZB-image.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/tVog6mAFbjhbUDZB-image.png)

```bash
    init=/bin/bash
```

press CTRL+X or F10 to boot

Mount, set simple password and remember it, touch file to make SElinux happy, sync, remount and initiate clean reboot.

[![image.png](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/scaled-1680-/eQVAkcKgoy19lAL4-image.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/eQVAkcKgoy19lAL4-image.png)

actually not like this, but
```bash
mount -o remount,rw /
passwd <user>

# option 1
restorecon -v /etc/shadow

# option 2
setfattr -n security.selinux -v system_u:object_r:shadow_t:s0 /etc/shadow
getfattr -n security.selinux /etc/shadow

sync
mount -o remount,ro /

/usr/sbin/reboot -f
```

Once system is loaded, login and set complex password

[![image.png](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/scaled-1680-/jpEfj2QnN3kygWxa-image.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-09/jpEfj2QnN3kygWxa-image.png)

Idea behind simple and complex passwords is that usually simple pass need to be typed (in hypervisor terminal/console) manually.

Once there is access over SSH, complex password can be generated and pasted from password manager.