Description
An insufficient minimum length can permit short, easily guessed IAM passwords. Omitting a setting does not mean no length restriction applies, so check the actual account policy. This policy governs IAM user console passwords, not root passwords or access keys.
Potential impact
- Short, weak passwords can be exploited in guessing attacks.
- Changing the length policy does not immediately change existing passwords.
Remediation
- Set min_pw_length or its alias minimum_password_length to a sufficient organizational minimum. Use one consistent name for the option.
- Review necessary character requirements and require MFA for console users. The new length requirement applies when users next change their passwords.
Examples
AWS permits custom minimum lengths from 6 to 128 characters. The module defaults to 6; the example’s 8 characters are not a universal recommendation.
Before
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
- name: Configure a second IAM password policy example
community.aws.iam_password_policy:
state: present
min_pw_length: 6
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
After
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 60
pw_reuse_prevent: 5
pw_expire: false
Explanation:
- Before: One task omits the minimum and the other explicitly sets 6. Check the actual policy that applies.
- After: The minimum is explicitly set to 8. Choose the required length according to organizational standards.