Octal600
Symbolic-rw-------
Binary110 000 000
Common TargetSSH Keys, .env Secrets

What Does CHMOD 600 Mean?

CHMOD 600 restricts file access exclusively to the file owner, granting read and write capabilities while denying all access to group members and other users.

6

Owner

Read + Write (4+2+0)

The owner has complete read and modify access to the file.

0

Group

No Access (0+0+0)

Group members cannot view, edit, or execute the file.

0

Others

No Access (0+0+0)

All other system users are blocked from reading or altering the file.

Why SSH Requires 600 for Private Keys

OpenSSH enforces strict permission validation on private key files (such as ~/.ssh/id_rsa or ~/.ssh/id_ed25519).

If your private key file is readable by group or public users, OpenSSH will abort the connection with an error message:

# SSH Error when key permissions are too open:@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ WARNING: UNPROTECTED PRIVATE KEY FILE! @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Permissions 0644 for '/home/user/.ssh/id_rsa' are too open.It is required that your private key files are NOT accessible by others.

Running chmod 600 ~/.ssh/id_rsa resolves this protection check by locking the file to your user account only.

Common Use Cases for CHMOD 600

  • SSH Private Keys: ~/.ssh/id_rsa, ~/.ssh/id_ed25519
  • Environment Credentials: .env files containing database passwords, API tokens, and secret keys
  • Database Configs: wp-config.php or application secrets
  • Personal Notes / Log Files: Files containing confidential logs or user data

How to Apply CHMOD 600

# Lock down SSH private keychmod 600 ~/.ssh/id_rsa# Lock down application secret filechmod 600 /var/www/html/.env

Try CHMOD 600 in the Interactive Tool

Inspect permissions and symbolic format for 600.

Open 600 in Calculator →