SSH

Published 2026-09-23

Permissions 0644 for id_rsa are too open.

When SSH on macOS reports Permissions 0644 for id_rsa are too open, tighten the private key to 0600.

Problem

When connecting to a remote server with an SSH private key on macOS, you may see:

> ssh [email protected]
 
The authenticity of host '[example.com]:42111 ([198.18.0.75]:42111)' can't be established.
ED25519 key fingerprint is: SHA256:vZ2CpKF5wJFW6T2iXSpIOI0YoZI+...
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[example.com]:42111' (ED25519) to the list of known hosts.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for '~/.ssh/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "~/.ssh/id_rsa": bad permissions
[email protected]: Permission denied (publickey,password).

Cause

An SSH private key is a sensitive file. OpenSSH checks who can access it, and refuses to load the key if other users can read it.

In ~/.ssh, run ls -l id_rsa. The permissions show as -rw-r--r--, which is 0644.

-rw-r--r--  1 root  staff  1675 Oct  1 10:00 id_rsa
  • 6: the owner can read and write.

  • 4: the group can read.

  • 4: everyone else can read.

The private key can therefore be read by other users.

Fix

Run chmod 600 ~/.ssh/id_rsa to set the private key to -rw-------, which is 0600.

Check again:

# Expected result
-rw-------

Only the file owner can read and write it. If the .ssh directory permissions are also wrong, set them with chmod 700 ~/.ssh.

  • chmod 600: owner can read and write. Common for private keys.

  • chmod 700: owner can read, write, and execute. Common for the .ssh directory.

  • Public keys (.pub): these do not need to stay secret, and 0644 is usually fine.

The rule: an SSH private key must not be readable by other users. 0600 is the usual setting.

What 0644 and 0600 mean

These are octal Unix/Linux file permissions. For example:

0644
β”‚β””β”¬β”˜
β”‚ β”‚
β”‚ └── three digits: owner / group / others
└──── a leading 0 marks an octal mode

Each digit is the sum of three permission bits:

4 = Read    (r)
2 = Write   (w)
1 = Execute (x)

So:

6 = 4 + 2 = rw-
4 = 4     = r--
0         = ---

Which means:

0644 = rw-r--r--
0600 = rw-------
0700 = rwx------

For an SSH private key:

  • 0644 β†’ the owner can read and write, and other users can read β†’ too open

  • 0600 β†’ only the owner can read and write β†’ right for a private key