Linux file permissions
chmod 700: what it means and when to use it
chmod 700 gives the owner full access and gives nobody else anything at all.
700
rwx------
| Who | Digit | Read | Write | Execute |
|---|---|---|---|---|
| Owner | 7 |
Yes | Yes | Yes |
| Group | 0 |
No | No | No |
| Everyone else | 0 |
No | No | No |
How chmod 700 works
The 7 is read, write and execute for the owner. The two zeros remove every permission from the group and from everyone else, so other users cannot even list what is inside a 700 directory.
It is the right setting for private folders and personal scripts. SSH, for example, expects your .ssh folder to be 700 and refuses to use keys kept somewhere other users can read.
Where 700 belongs
- The .ssh folder in your home directory
- Private scripts that contain credentials
- Home directories on shared servers
The command
Both of these set exactly the same permissions. The number is shorter; the letters are easier to read back later.
chmod 700 filename
chmod u=rwx,g=,o= filename
Services running as another user, such as a web server, cannot read anything inside a 700 directory.