chmod 400 r--------

chmod 400 (r--------): the owner can read; group and others can do nothing. Typical use: private keys that must not change. Commands and umask.

Octal
400 (also written 0400)
Symbolic
r--------
ls -l shows
-r-------- for a file, dr-------- for a directory
chmod letters
u=r,g=,o=

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)4r--Read the contentsList the names inside and see names only, not open or inspect the files
Group (g)0---NothingNothing
Others (o)0---NothingNothing

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

Read-only for the owner and nothing for anyone else. It suits files that should never change by accident, such as an SSH private key (OpenSSH accepts 400 or 600) or the .pem key file a cloud provider hands out, which AWS's own instructions tell you to chmod 400. WordPress suggests 400 or 440 for wp-config.php. The owner can still chmod it back, so it guards against mistakes, not attackers.

Security notes

  • Nobody but the owner (and root) has any access, the safest setting for secrets.

Commands

  • Numeric
    chmod 400 file
  • Symbolic
    chmod u=r,g=,o= file
  • Check the result
    stat -c '%a %A %n' file
  • Files only, recursively
    find /path -type f -exec chmod 400 {} +

The umask that gives 400

No umask produces 400: a umask only removes bits from 666 for files and 777 for directories, and it never sets execute on a new file. Set it with chmod after creating the file or directory.

Its directory counterpart is chmod 500 (r-x------).

Other common modes

Work out any other mode in the chmod calculator