# DK0029 Error - Unprotected private key file

**URL:** https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284
**Category:** Bug Reports
**Created:** [February 10, 2022, 5:00pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284 "2022-02-10T17:00:39Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 10, 2022, 5:00pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/1 "2022-02-10T17:00:39Z")

</div>

**Q: Date/Time this occurred (Provide your time zone also)**  
\*\*A: 2/9/2022 - 2/10/2022 multiple times \*\*

**Q: DevKinsta Version**  
\*\*A: 2.4.0 \*\*

**Q: OS Version**  
\*\*A: Windows 11 Pro 22000.493 \*\*

**Q: Docker Desktop Version**  
\*\*A: 4.4.4 (73704) \*\*

**Q: Were any error codes or messages observed? If so, what were they?**  
\*\*A: DK0029 \*\*

**Q: Detailed Description of the Problem**  
Trying to import a site and getting the DK0029 error, but it seems to be different than the other issues people have had regarding that error. The Kinsta log:

```auto
[2022-02-10 10:51:54.131] [error] Error - DK0029: MYSQL_DUMP_COMMON: @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ WARNING: UNPROTECTED PRIVATE KEY FILE! @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Permissions 0755 for '/root/.ssh/id_rsa' are too open.It is required that your private key files are NOT accessible by others.This private key will be ignored.Load key "/root/.ssh/id_rsa": bad permissions
    at file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:2:863746
    at tryCatch (file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:8:2526220)
    at Generator._invoke (file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:8:2525843)
    at Generator.next (file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:8:2526986)
    at asyncGeneratorStep (file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:2:1003)
    at _next (file:///C:/Users/Matt/AppData/Local/Programs/DevKinsta/resources/app.asar/dist/renderer.prod.js:2:1302)
    at processTicksAndRejections (node:internal/process/task_queues:96:5)

```

I’m not quite sure which id\_rsa it’s referring to though. The only container I could find with the file is devkinsta\_fpm and I tried `chmod 600 /root/.ssh/id_rsa` but that didn’t fix it.

I’ve also tried deleting all sites in DevKinsta, all devkinsta\_ containers, uninstalling DevKinsta and reinstalling and no dice either.

Help please!

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 10, 2022, 9:54pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/2 "2022-02-10T21:54:16Z")

</div>

Hi @mattd, thanks for reaching out. I’m trying to figure out what would actually cause this as well. Is this happening with ANY site you try to import?

Are you able to create a new WordPress website within DevKinsta without issue? If you can share your main.log file after this failure, I can share it with our devs to hopefully get more insight.

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 10, 2022, 10:29pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/3 "2022-02-10T22:29:39Z")

</div>

Hi @Kevin,

Yeah, it’s happening for every site 😕

Creating a new WordPress site within DevKinsta works fine.

And I’ve DM’d you the main.log file.

Thanks!

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 10, 2022, 10:55pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/4 "2022-02-10T22:55:20Z")

</div>

Thanks for sharing that, @mattd! I’m going to have our Devs look into what might be happening there.  
I also would recommend doing a factor reset of Docker before trying again. I checked your site within MyKinsta for abnormalities and nothing stood out to me, although there could be something that the Devs can spot.

Were you copying the Live site from MyKinsta or the Staging?

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 10, 2022, 10:57pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/5 "2022-02-10T22:57:28Z")

</div>

Great, thanks @Kevin. It happens for both Live and Staging for every site.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 15, 2022, 11:27pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/6 "2022-02-15T23:27:57Z")

</div>

Hi @mattd, I believe I’ve figured out what is causing this. There’s something wrong with the id\_rsa that is within DevKinsta’s .ssh directory.

Quick fix:

1. Close DevKinsta then navigate to your DevKinsta directory (C:\Users\myuser\DevKinsta)
2. Delete the .ssh directory
3. Open DevKinsta and log out of your MyKinsta account
4. Logging back in should recreate the .ssh directory with the correct permissions  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/1X/ea199f7e47c8db4040f48ce6faf74181585e8fe0.png)

Please let me know if doing this still leads to the same private key error. You’re not the only person to have this error on Windows but I’m still not sure what exactly is causing it.

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 16, 2022, 2:28pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/7 "2022-02-16T14:28:33Z")

</div>

Thanks for the suggestion @Kevin. I’m afraid it didn’t work though 😕 I followed the steps and the .ssh directory was recreated like you expected, but attempting to import a site still gives the same error.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 16, 2022, 4:00pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/8 "2022-02-16T16:00:00Z")

</div>

Huh very odd. So can you open WSL console then navigate to the DevKinsta/.ssh directory and check the permissions that are being set for id\_rsa?

1. Open a WSL console
2. `cd /mnt/c/Users/username/DevKinsta/.ssh`
3. ‘stat id\_rsa’
4. “Access” will tell you the permissions  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/1X/1ae64d93a280faf8c6f464ee47032d17f3e4608b.png)

Whatever WSL sees here seems to be what DevKinsta sees as the file permissions. I feel like the permissions aren’t being set correctly by your PC for some reason.

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 16, 2022, 4:19pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/9 "2022-02-16T16:19:01Z")

</div>

```auto
Matt@Matt-PC D:/Dev/DevKinsta/.ssh
10:16:05 ❯ ls -la
total 5
drwxr-xr-x 1 Matt 197609 0 Feb 16 08:23 ./
drwxr-xr-x 1 Matt 197609 0 Feb 16 08:20 ../
-rw-r--r-- 1 Matt 197609 2602 Feb 16 08:23 id_rsa
-rw-r--r-- 1 Matt 197609 571 Feb 16 08:23 id_rsa.pub

Matt@Matt-PC D:/Dev/DevKinsta/.ssh
10:16:06 ❯ stat id_rsa
  File: id_rsa
  Size: 2602 Blocks: 4 IO Block: 65536 regular file
Device: 9c1b5385h/2619036549d Inode: 153122387330928527 Links: 1
Access: (0644/-rw-r--r--) Uid: (197609/ Matt) Gid: (197609/ UNKNOWN)
Access: 2022-02-16 10:16:06.642244400 -0600
Modify: 2022-02-16 08:23:19.725450900 -0600
Change: 2022-02-16 08:23:19.725450900 -0600
 Birth: 2022-02-16 08:23:19.722949400 -0600

```

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 16, 2022, 4:20pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/10 "2022-02-16T16:20:53Z")

</div>

In your main.log, is it saying the id\_rsa permissions are 644? Or is it still saying they are 755?

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 16, 2022, 4:25pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/11 "2022-02-16T16:25:27Z")

</div>

Just tried importing again, it says 755:

`[2022-02-16 10:24:46.352] [error] Error - DK0029: MYSQL_DUMP_COMMON: @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ WARNING: UNPROTECTED PRIVATE KEY FILE! @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Permissions 0755 for '/root/.ssh/id_rsa' are too open.It is required that your private key files are NOT accessible by others.This private key will be ignored.Load key "/root/.ssh/id_rsa": bad permissions`

So /root/.ssh maps to C:/Users/user/DevKinsta/.ssh, or is the error referring to a different location?

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 16, 2022, 4:47pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/12 "2022-02-16T16:47:43Z")

</div>

So I was looking at this based on a site Push; that’s where the id\_rsa is in that case. Looking at your original error it’s probably due to the id\_rsa on Kinsta since you’re doing a Site Pull. I’m working on this right now/trying to reproduce the error exactly as it’s showing for you.

I’ll see if any permissions on Kinsta need to be changed. Do you mind if I only look into your Staging site? Don’t want to do anything that affects the Live site.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 16, 2022, 5:07pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/13 "2022-02-16T17:07:14Z")

</div>

By the way @mattd, version 2.4.1 was just released. I really doubt any of the bugfixes will affect this but it’s worth updating/trying just in case.

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 17, 2022, 3:53pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/14 "2022-02-17T15:53:45Z")

</div>

Hey @Kevin, unfortunately the new version didn’t fix it, but unsurprising if the issue is server-side.

But sure, you can check out our staging. I’ll DM you with the account.

Thanks!

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 17, 2022, 6:55pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/15 "2022-02-17T18:55:43Z")

</div>

Thanks @mattd;  
So I’ve finally been able to reproduce the exact error you are having and I think my original conclusion is correct. For some reason the permissions for .ssh/id\_rsa are not being set correctly. Are you logged in as the root/admin user? Looking back at your `stat id_rsa`, I notice that your Access/ Uid and Gid don’t match what I get as the root/main user on my computer:

> Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)

vs

> Access: (0644/-rw-r–r–) Uid: (197609/ Matt) Gid: (197609/ UNKNOWN)

Maybe you need to delete the .ssh directory again and make sure you’re running DevKinsta as the administrator when you log into your Kinsta account? Also if you have another PC that you can use to test, that would help, too.

The mysqldump command uses the SSH credentials on your computer to connect to the Kinsta site. I’ve spent a couple of hours trying to figure out how to manually set the file permissions from within Windows but for whatever reason nothing as simple as “chmod” and “chown” exists for Windows. It is interesting that your permissions aren’t being set the same way as mine on my computers, though.

I think if you install DevKinsta on the main/admin Windows account you can get past this. I’ll keep trying to reproduce this but admin privileges/permissions seems like the best thing to look into.

I did mention this to our devs and they may look into ignoring this permissions notice so that it doesn’t cause import/export to fail.

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 18, 2022, 3:10pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/16 "2022-02-18T15:10:22Z")

</div>

Hi @Kevin, I tried logging out of DevKinsta, exiting the app, deleted the .ssh directory, opened DevKinsta with admin privileges, and logged back in… and no dice ☹

The .ssh directory was re-created, but `stat id_rsa` is still showing my UID, not root.

I tried importing a site again anyways and still the same error.

FYI, I’m running Docker Desktop with the Hyper-V backend (vs WSL 2) as [discussed here](https://community.kinsta.com/t/website-interactivity-is-slow/293) if that matters.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 19, 2022, 1:12am UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/17 "2022-02-19T01:12:58Z")

</div>

Thanks for trying @mattd; I’m still not sure what’s causing this for certain Windows users but the permissions on that file are definitely the issue. I’ve used this week’s troubleshooting to bring this up with the Devs. I’ll be sure to update you if they can think of a workaround or solution.

Thanks again for working with me on this one. It’s a very odd issue.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 21, 2022, 9:47pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/18 "2022-02-21T21:47:13Z")

</div>

Hey @mattd, I’ve been discussing ways to resolve this in future versions with our devs but I’ve been looking into quick fixes. Using Hyper-V might be causing the difference in permissions when the file is created but I haven’t been able to reproduce your setup yet.

Can you see if running this in the DevKinsta/.ssh directory helps with the folder permissions? If you can stat the file again after that would be helpful:

`sudo cat id_rsa > id_rsa2 && chmod 600 id_rsa2 && rm id_rsa && mv id_rsa2 id_rsa`

If the user/group still look weird, you might have to `chown yourusername:yourusername id_rsa`

---

<div class="post-metadata">

### Author: ![mattd](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/mattd/32/273_2.png) [@mattd](https://community.kinsta.com/u/mattd)
#### Post date: [February 22, 2022, 4:51pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/19 "2022-02-22T16:51:38Z")

</div>

Hi @Kevin, working from the office today (first time since the issue) and crazy enough, I’m getting the same exact error on my work machine. Totally different computer, network, etc. Similarities are that it’s Windows 10 Pro and Hyper-V backend for Docker Desktop.

I tried running the command(s) you suggested but still no luck. (I think the 2nd command was supposed to be `chown` not `chmod`?)

Not sure if I mentioned this before, but both my work and home PCs ran DevKinsta just fine until recently when this error popped up. Honestly not sure if it was after a specific update though…

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [February 22, 2022, 5:11pm UTC](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284/20 "2022-02-22T17:11:45Z")

</div>

Thanks @mattd,  
Yes, chown, sorry! Yes there have been a lot of updates lately but I’m not sure what would cause this. There’s a small handful of people having the same issue but I don’t think everyone is using a Hyper-V backend setup.

I guess I’ll just try to emulate your setup sometime. By the way, did manually creating a new id\_rsa still leave you with 644 permissions on that file?

[Next page](https://community.kinsta.com/t/dk0029-error-unprotected-private-key-file/1284.md?page=2)
