CompTIA Linux+ (XK0-006)SecurityEasy
An administrator runs 'ssh user@server' and receives the error: 'WARNING: UNPROTECTED PRIVATE KEY FILE!' referencing ~/.ssh/id_rsa. What is the correct fix?
- Achown root:root ~/.ssh/id_rsa
- Bchmod 644 ~/.ssh/id_rsa
- Cchmod 600 ~/.ssh/id_rsa
- Dchmod 777 ~/.ssh/id_rsa
Show answer & explanationAnswer & explanation
Correct answer: C. chmod 600 ~/.ssh/id_rsa
SSH refuses to use a private key that is readable or writable by group or others, as this represents a security risk. Setting permissions to 600 (read/write for owner only) resolves the warning and allows the key to be used.
Why the other options are wrong
- A. Changing ownership doesn't address the overly permissive mode bits causing the warning.
- B. 644 still allows group/other read access, which triggers the same warning.
- D. 777 grants full access to everyone, making the security problem far worse.
SSH Private Key Permissions
SSH requires private key files to be readable only by their owner (mode 600) to prevent unauthorized users from stealing key material.
- Private key files must be chmod 600
- ~/.ssh directory itself should be chmod 700
- Public keys (.pub) can safely be world-readable (644)
Memory trick: Private keys are secrets — lock them to 600, owner-only.