SSH

发布于 2026-09-23

Permissions 0644 for id_rsa are too open.

macOS 用 SSH 私钥登录时,若提示 Permissions 0644 for id_rsa are too open,把私钥权限收成 0600 即可。

问题

macOS 使用 SSH 私钥连接远程服务器时,提示:

> ssh [email protected]
 
The authenticity of host '[example.com]:42111 ([198.18.0.75]:42111)' can't be established.
ED25519 key fingerprint is: SHA256:vZ2CpKF5wJFW6T2iXSpIOI0YoZI+...
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[example.com]:42111' (ED25519) to the list of known hosts.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for '~/.ssh/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "~/.ssh/id_rsa": bad permissions
[email protected]: Permission denied (publickey,password).

原因

SSH 私钥属于敏感文件。OpenSSH 会检查私钥的访问权限,如果其他用户也可以读取该文件,就会拒绝加载。

在 ~/.ssh 目录下执行 ls -l id_rsa,显示权限为 -rw-r--r--,即:0644。

-rw-r--r--  1 root  staff  1675 Oct  1 10:00 id_rsa
  • 6:文件所有者可读、可写。

  • 4:所属用户组可读。

  • 4:其他用户可读。

因此,私钥存在被其他用户读取的风险。

解决

执行 chmod 600 ~/.ssh/id_rsa 命令,将私钥文件权限设置为 -rw-------,即:0600。

再检查:

# 预期结果
-rw-------

即仅文件所有者可读、可写。如果 .ssh 目录权限也存在问题,可以设置为:chmod 700 ~/.ssh。

相关知识

  • chmod 600:仅所有者可读、可写,常用于私钥。

  • chmod 700:仅所有者可读、可写、可执行,常用于 .ssh 目录。

  • 公钥 .pub:不需要保密,通常可以使用 0644。

核心原则:SSH 私钥不能对其他用户开放读取权限,通常设置为 0600。

0644 / 0600 是什么

这是 Unix/Linux 文件权限的八进制表示法。例如:

0644
│└┬┘
│ │
│ └── 三位分别表示:所有者 / 用户组 / 其他用户
└──── 前导 0 表示八进制权限写法

每一位由三种权限相加得到:

4 = Read    (r) 读取
2 = Write   (w) 写入
1 = Execute (x) 执行

因此:

6 = 4 + 2 = rw-
4 = 4     = r--
0         = ---

所以:

0644 = rw-r--r--
0600 = rw-------
0700 = rwx------

对于 SSH 私钥:

  • 0644 → 所有者可读写,其他用户也可读 → 权限过大

  • 0600 → 只有所有者可读写 → 适合私钥