CompTIA Linux+ (XK0-006)TroubleshootingEasy

A technician configures key-based SSH authentication for a user. When the user attempts to log in, the client displays: "UNPROTECTED PRIVATE KEY FILE!" and the connection is refused. A long listing shows `-rw-r--r-- 1 user user 1823 Jun 1 09:00 /home/user/.ssh/id_rsa`. Which command resolves the issue?

  1. Achmod 600 /home/user/.ssh/id_rsa
  2. Bchown root:root /home/user/.ssh/id_rsa
  3. Cchmod 755 /home/user/.ssh/id_rsa
  4. Dchmod 644 /home/user/.ssh/id_rsa.pub
Show answer & explanation

Correct answer: A. chmod 600 /home/user/.ssh/id_rsa

SSH refuses to use a private key that is readable by group or other users. Setting permissions to 600 (owner read/write only) satisfies SSH's security requirement and allows the login to proceed.

Why the other options are wrong

  • B. Changing ownership to root does not fix the group/other read permission problem.
  • C. 755 is far too permissive for a private key and would still be rejected.
  • D. The public key's permissions are irrelevant to this error; the private key is the issue.

SSH Private Key Permissions

OpenSSH requires private key files to be readable only by their owner (mode 600) or it will refuse to use them for authentication.

  • Private key: chmod 600
  • ~/.ssh directory: chmod 700
  • Public key (.pub) permissions are not security-sensitive

Memory trick: Six-hundred keeps your key a secret.

More Troubleshooting questions