Description
pw_max_age sets the maximum age of IAM console passwords; 0 validly disables automatic expiration. If an organization requires expiration, the effective policy and user change process must meet that requirement. Password expiration does not expire access keys.
Potential impact
- An exposed password may remain usable without an appropriate replacement process.
- An excessively short period or abrupt policy change can disrupt legitimate sign-ins.
Remediation
- If expiration is required, set pw_max_age or its alias password_max_age to an organizationally appropriate value from 1 to 1095 days, and prepare password-change and recovery procedures.
- Maintain MFA and replace exposed passwords immediately rather than waiting for expiration. pw_expire separately controls whether users can change an expired password themselves.
Examples
The before tasks are alternatives with an omitted maximum age or 180 days. The module defaults an omitted pw_max_age to 0. Applying expiration also affects passwords already older than the selected period.
Before
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_reuse_prevent: 5
pw_expire: false
- name: Configure a second IAM password policy example
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 180
pw_reuse_prevent: 5
pw_expire: false
After
yaml
- name: Configure the IAM password policy
community.aws.iam_password_policy:
state: present
min_pw_length: 8
require_symbols: false
require_numbers: true
require_uppercase: true
require_lowercase: true
allow_pw_change: true
pw_max_age: 20
pw_reuse_prevent: 5
pw_expire: false
Explanation:
- Before: The first task does not enable automatic expiration, and the second uses 180 days. Suitability depends on organizational policy.
- After: The maximum age is 20 days. This is illustrative, not a universal recommendation. pw_expire: false does not remove that expiration period.