Information
All users should have a password change date in the past.
If a user's recorded password change date is in the future, then they could bypass any set password expiration.
Solution
Investigate any users with a password change date in the future and correct them. Locking the account, expiring the password, or resetting the password manually may be appropriate.
Examples
Reset last change date to today for a single user:
# chage -d "$(date +%Y-%m-%d)" <user>
Force password change on next login (recommended companion):
# chage -d 0 <user>
Impact:
An account with a future last-change date can permanently bypass password expiration policies - the shadow system calculates expiry relative to the last-change date, so a far-future date means the password never expires regardless of PASS_MAX_DAYS.