Review the number requirement for Alicloud RAM passwords

Align the number requirement with organizational password rules.

Description

With require_numbers = false, RAM console passwords do not have to contain a digit. Organizations that require digits should align the setting with that policy.

Potential impact

Passwords may be accepted without meeting organizational character requirements. The presence of a digit alone does not establish password strength.

Remediation

Set require_numbers = true when digits are required. Also maintain sufficient length and unpredictable password choices.

Examples

The examples change only the digit requirement. Other settings remain for comparison and are not a complete recommended password policy.

Before

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  minimum_password_length      = 9
  require_lowercase_characters = false
  require_uppercase_characters = false
  require_numbers              = false
  require_symbols              = false
  hard_expiry                  = true
  max_password_age             = 12
  password_reuse_prevention    = 5
  max_login_attempts           = 3
}

After

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  minimum_password_length      = 9
  require_lowercase_characters = false
  require_uppercase_characters = false
  require_numbers              = true
  require_symbols              = false
  hard_expiry                  = true
  max_password_age             = 12
  password_reuse_prevention    = 5
  max_login_attempts           = 3
}

References