A security policy requires that a user's password must expire 90 days after last change, and the user must change it immediately on next login. The last password change was 30 days ago. Which set of commands achieves this?
Setting `-M 90` defines the maximum password age as 90 days, satisfying the expiry constraint. Setting `-d 0` backdates the last-change date to the epoch, forcing an immediate password change at next login. Together they meet both policy requirements for user1.
Why this answer
`chage -M 90 user1` sets the maximum password age to 90 days, and `chage -d 0 user1` forces the password to expire immediately (setting the last change date to epoch 0), which requires the user to change the password on the next login. This satisfies both requirements: the password will expire 90 days after the forced change, and the user must change it immediately.
Exam trap
The trap here is that candidates may confuse `-d 0` with other `chage` options like `-M`, `-m`, `-W`, or `-I`, not realizing that only `-d 0` forces an immediate password change on next login.
How to eliminate wrong answers
Option B is wrong because `chage -m 1` sets the minimum number of days between password changes to 1, which does not force immediate expiration or enforce the 90-day expiry; it only prevents the user from changing the password more than once per day. Option C is wrong because `chage -W 7` sets a warning period of 7 days before password expiration, which does not force immediate password change on next login. Option D is wrong because `chage -I 5` sets the inactive lockout period to 5 days after expiration, which does not force immediate password change on next login.