Problem
When connecting to a remote server with an SSH private key on macOS, you may see:
> ssh [email protected]
The authenticity of host '[example.com]:42111 ([198.18.0.75]:42111)' can't be established.
ED25519 key fingerprint is: SHA256:vZ2CpKF5wJFW6T2iXSpIOI0YoZI+...
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[example.com]:42111' (ED25519) to the list of known hosts.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for '~/.ssh/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "~/.ssh/id_rsa": bad permissions
[email protected]: Permission denied (publickey,password).Cause
An SSH private key is a sensitive file. OpenSSH checks who can access it, and refuses to load the key if other users can read it.
In ~/.ssh, run ls -l id_rsa. The permissions show as -rw-r--r--, which is 0644.
-rw-r--r-- 1 root staff 1675 Oct 1 10:00 id_rsa-
6: the owner can read and write.
-
4: the group can read.
-
4: everyone else can read.
The private key can therefore be read by other users.
Fix
Run chmod 600 ~/.ssh/id_rsa to set the private key to -rw-------, which is 0600.
Check again:
# Expected result
-rw-------Only the file owner can read and write it. If the .ssh directory permissions are also wrong, set them with chmod 700 ~/.ssh.
Related notes
-
chmod 600: owner can read and write. Common for private keys.
-
chmod 700: owner can read, write, and execute. Common for the
.sshdirectory. -
Public keys (
.pub): these do not need to stay secret, and 0644 is usually fine.
The rule: an SSH private key must not be readable by other users. 0600 is the usual setting.
What 0644 and 0600 mean
These are octal Unix/Linux file permissions. For example:
0644
βββ¬β
β β
β βββ three digits: owner / group / others
βββββ a leading 0 marks an octal modeEach digit is the sum of three permission bits:
4 = Read (r)
2 = Write (w)
1 = Execute (x)So:
6 = 4 + 2 = rw-
4 = 4 = r--
0 = ---Which means:
0644 = rw-r--r--
0600 = rw-------
0700 = rwx------For an SSH private key:
-
0644 β the owner can read and write, and other users can read β too open
-
0600 β only the owner can read and write β right for a private key