IAM password below the minimum length

Use sufficiently long, unique IAM console passwords.

Description

Short or predictable IAM console passwords can be vulnerable to guessing. Adding length does not adequately protect a reused or widely known password.

Potential impact

A guessed password can allow misuse of the account’s permissions.

Remediation

Use unique passwords meeting the organization’s length requirement and enable MFA. If the baseline is at least 14 characters, enforce that or longer in the account password policy.

Examples

These excerpts illustrate length only. Do not use the displayed passwords for real accounts; supply production passwords through secure input or secret management. Referenced resources are omitted.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Password length comparison
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"
      LoginProfile:
        Password: myP@ssW0rd
      Policies:
      - PolicyName: giveaccesstoqueueonly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sqs:*
            Resource:
            - !GetAtt myqueue.Arn
          - Effect: Deny
            Action:
            - sqs:*
            NotResource:
            - !GetAtt myqueue.Arn
      - PolicyName: giveaccesstotopiconly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sns:*
            Resource:
            - !Ref mytopic
          - Effect: Deny
            Action:
            - sns:*
            NotResource:
            - !Ref mytopic

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Password length comparison
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"
      LoginProfile:
        Password: myP@ssW0rd123asw
      Policies:
      - PolicyName: giveaccesstoqueueonly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sqs:*
            Resource:
            - !GetAtt myqueue.Arn
          - Effect: Deny
            Action:
            - sqs:*
            NotResource:
            - !GetAtt myqueue.Arn
      - PolicyName: giveaccesstotopiconly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sns:*
            Resource:
            - !Ref mytopic
          - Effect: Deny
            Action:
            - sns:*
            NotResource:
            - !Ref mytopic

References