chmod 700 rwx------

chmod 700 (rwx------): the owner can read, write and execute; group and others can do nothing. Typical use: ~/.ssh and private directories.

Octal
700 (also written 0700)
Symbolic
rwx------
ls -l shows
-rwx------ for a file, drwx------ for a directory
chmod letters
u=rwx,g=,o=

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)7rwxRead the contents, change or empty the contents and run it as a programList the names inside, create, delete and rename entries and enter it and open files by name
Group (g)0---NothingNothing
Others (o)0---NothingNothing

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

The owner has full access, everyone else none. It is the mode OpenSSH expects for ~/.ssh, the default for new home directories on Fedora and RHEL, and the right choice for private scripts and backup folders.

Security notes

  • Nobody but the owner (and root) has any access, the safest setting for secrets.

Commands

  • Numeric
    chmod 700 file
  • Symbolic
    chmod u=rwx,g=,o= file
  • Check the result
    stat -c '%a %A %n' file
  • Directories only, recursively
    find /path -type d -exec chmod 700 {} +

Avoid chmod -R 700 on a tree that holds files as well as folders: it makes every file executable. Use the find command above for directories and a file mode such as 600 for the files.

The umask that gives 700

  • umask 077: new directories are created as 700 (and files as 600)

Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.

Its file counterpart is chmod 600 (rw-------).

Other common modes

Work out any other mode in the chmod calculator