Search tools

Linux file permissions

chmod 400: what it means and when to use it

chmod 400 makes a file read only for its owner and completely closed to everyone else.

400 r--------
What chmod 400 allows for each class of user
WhoDigitRead WriteExecute
Owner 4 Yes No No
Group 0 No No No
Everyone else 0 No No No

How chmod 400 works

The 4 gives the owner read permission and nothing more. Not even the owner can change the file without changing the permission first, which protects it from accidental edits.

Cloud providers such as AWS ask you to set downloaded SSH key files to 400 before you use them. It is also a sensible choice for certificates and other secrets that should never change once they are in place.

Where 400 belongs

  • SSH key files downloaded from a cloud provider
  • TLS certificates and private keys
  • Files you want to protect from accidental edits

The command

Both of these set exactly the same permissions. The number is shorter; the letters are easier to read back later.

chmod 400 filename
chmod u=r,g=,o= filename

Some programs rewrite their own config files. Those files need 600, because 400 would stop the owner from saving changes.

Open 400 in the chmod calculator