Description
With require_numbers = false, RAM console passwords do not have to contain a digit. Organizations that require digits should align the setting with that policy.
Potential impact
Passwords may be accepted without meeting organizational character requirements. The presence of a digit alone does not establish password strength.
Remediation
Set require_numbers = true when digits are required. Also maintain sufficient length and unpredictable password choices.
Examples
The examples change only the digit requirement. Other settings remain for comparison and are not a complete recommended password policy.
Before
hcl
resource "alicloud_ram_account_password_policy" "corporate" {
minimum_password_length = 9
require_lowercase_characters = false
require_uppercase_characters = false
require_numbers = false
require_symbols = false
hard_expiry = true
max_password_age = 12
password_reuse_prevention = 5
max_login_attempts = 3
}
After
hcl
resource "alicloud_ram_account_password_policy" "corporate" {
minimum_password_length = 9
require_lowercase_characters = false
require_uppercase_characters = false
require_numbers = true
require_symbols = false
hard_expiry = true
max_password_age = 12
password_reuse_prevention = 5
max_login_attempts = 3
}