Windows `ssh` 9.5.5.1 doesn't like CodexSandboxUsers on ~/.ssh/id_rsa

Open 💬 9 comments Opened Feb 19, 2026 by HenkPoley

What version of Codex CLI is running?

0.99.0 and later on 0.104.0

What subscription do you have?

Plus

Which model were you using?

gpt-5.3-codex

What platform is your computer?

Microsoft Windows NT 10.0.26200.0 x64

What terminal emulator and version are you using (if applicable)?

Windows Terminal

What issue are you seeing?

C:\User\user> ssh -V
OpenSSH_for_Windows_9.5p2, LibreSSL 3.8.2
C:\Users\user> ssh example.com
Bad permissions. Try removing permissions for user: <Hostname>\\CodexSandboxUsers (S-1-5-21-<Windows Security Identifier>) on file C:/Users/user/.ssh/id_rsa.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions for 'C:\\Users\\user/.ssh/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "C:\\Users\\user/.ssh/id_rsa": bad permissions

I did some icacls shenanigans to set permissions back to something SSH is happy with.

I also updated codex with npm i -g @openai/codex. Now codex is borked on some starlark rule (deleted this rule from default.rules and it works again):

C:\User\user> codex --version
codex-cli 0.104.0
C:\User\user> codex --full-auto resume 019c322b-<UUID>-c62f430b46ce
Error loading rules:
C:\Users\user\.codex\rules\default.rules:38: starlark error: error: Parse error: unexpected identifier 'HOME' here, expected one of "\n", "!=", "%", "%=", "&", "&=", "(", ")", "*", "*=", "+", "+=", ",", "-", "-=", ".", "/", "//", "//=", "/=", ":", ";", "<", "<<", "<<=", "<=", "=", "==", ">", ">=", ">>", ">>=", "[", "]", "^", "^=", "and", "else", "for", "if", "in", "not", "or", "|", "|=" or "}" (problem is on or around line 38)

What steps can reproduce the bug?

I guess:

  1. Use the OpenAI Codex CLI with Windows sandbox (--full-auto ?).
  2. It sets up some extra user.
  3. SSH freaks out.

What is the expected behavior?

Find a way to sandbox that does not freak out Windows's ssh.

Additional information

The issue did _not_ re-appear immediately when I did a codex --full-auto resume <UUID> with OpenAI Codex CLI (v0.104.0)

View original on GitHub ↗

9 Comments

Timtam · 4 months ago

Same issue here. I was also confused about the entire sandbox thing not working at all, as in, codex always gets "no output". I then resorted to removing the user permissions from my entire C:\Usersẞ\<Username> folder as .ssh was inheriting the ones from said folder. Now ssh is back and working again, however codex still gives me no output and can't work at all as it seems. It basically broke my codex :).

rayjasson98 · 4 months ago

Same issue. I’ve always used Codex in WSL, but I tried running it on native Windows and it ended up messing up my SSH config. I won’t be using Codex on Windows again. :(

itchenfei · 4 months ago

same issue here

tzarebczan · 4 months ago

Just ran into this as well. What's worse, if you use git bash, it fails silently.

l0wdin · 4 months ago

Same thing happened here.
I had to disable inheritance on these files and remove CodexSandboxUsers (in my case, I also had to remove another SID starting with S-1-5-21..., but I couldn’t link that user to Codex itself):

%userprofile%/.ssh/config
%userprofile%/some_path_here/ssh.key

Just ran into this as well. What's worse, if you use git bash, it fails silently.

I figured out this was the problem because I was trying to use Remote Explorer in VS Code to connect to a remote Linux server. It fails silently there too.

hczs · 3 months ago

Fuck CODEX!

JakeyPrime · 3 months ago

Also having this issue, even with Codex completely uninstalled.

linQian99 · 3 months ago

TOO RIDICULOUS. This make me even could not ssh, how could theses guys even not test such a simple function????

alexkras · 3 months ago

it doesn't work with windows native command line (powershell, terminal) - it show error:
Bad permissions. Try removing permissions for user: ... CodexSandboxUsers ...
at the same time minegw64 (in git-bash particular) works well, looks like it's ignore Win UAC.