WARNING: UNPROTECTED PRIVATE KEY FILE! Permissions 0644 for 'key.pem' are too open
SSH refuses to use a private key that other users can read; it must be readable only by you (chmod 600).
Seen on:
Linux
Meaning
Keys downloaded from cloud consoles, copied from Windows or stored on a mounted drive often get 0644/0777 permissions. On WSL/NTFS mounts chmod may not stick — copy the key into the Linux home directory.
Common causes
- Key file mode 0644/0664/0777
- Key on an NTFS/Windows mount (WSL) where permissions aren’t enforced
- Wrong owner after copying with sudo
⚡ Quick fix
- chmod 600 the key (400 also works)
- Make sure you own it: chown $USER
- On WSL, copy the key to ~/.ssh inside Linux
Detailed fix by platform
Shell
- bash
chmod 600 ~/.ssh/key.pem chmod 700 ~/.ssh
Windows
- powershell
icacls .\key.pem /inheritance:r icacls .\key.pem /grant:r "$($env:USERNAME):(R)"
How to diagnose
- Mode — ls -l key.pem
- Owner — Your user?
- Filesystem — On /mnt/c?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS65001 AADSTS65001: The user or administrator has not consented to use the application
- Access to the path is denied System.UnauthorizedAccessException: Access to the path 'x' is denied
- avc: denied SELinux is preventing ... / avc: denied { read } for pid=... (permission denied despite correct permissions)
Most viewed in Linux
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026