chmod 600 rw-------

chmod 600 (rw-------): the owner can read and write; group and others can do nothing. Typical use: SSH keys and private files. Commands and umask.

Octal
600 (also written 0600)
Symbolic
rw-------
ls -l shows
-rw------- for a file, drw------- for a directory
chmod letters
u=rw,g=,o=

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)6rw-Read the contents and change or empty the contentsList the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files
Group (g)0---NothingNothing
Others (o)0---NothingNothing

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

The owner can read and write, nobody else can do anything. This is the standard for private files: SSH private keys (ssh refuses a key others can read, with the warning UNPROTECTED PRIVATE KEY FILE), ~/.ssh/authorized_keys and ~/.ssh/config, .env files with passwords, and per-user crontab files.

Security notes

  • Nobody but the owner (and root) has any access, the safest setting for secrets.

Commands

  • Numeric
    chmod 600 file
  • Symbolic
    chmod u=rw,g=,o= file
  • Check the result
    stat -c '%a %A %n' file
  • Files only, recursively
    find /path -type f -exec chmod 600 {} +

The umask that gives 600

  • umask 077: new files are created as 600 (and directories as 700)

Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.

Its directory counterpart is chmod 700 (rwx------).

Other common modes

Work out any other mode in the chmod calculator