Review the symbol requirement for Alicloud RAM passwords

Match the symbol requirement to organizational password policy.

Description

With require_symbols = false, RAM console passwords can omit special characters. Enable this setting when the organization requires symbols.

Potential impact

Accepted passwords may not match the character policy. Adding one symbol to a common word does not by itself make the password hard to guess.

Remediation

Set require_symbols = true when required and use sufficiently long, unpredictable passwords.

Examples

The examples enable the symbol requirement. Other values provide comparison context and are not a complete recommended configuration.

Before

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  minimum_password_length      = 9
  require_lowercase_characters = false
  require_uppercase_characters = false
  require_numbers              = false
  require_symbols              = false
  hard_expiry                  = true
  max_password_age             = 12
  password_reuse_prevention    = 5
  max_login_attempts           = 3
}

After

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  minimum_password_length      = 9
  require_lowercase_characters = false
  require_uppercase_characters = false
  require_numbers              = false
  require_symbols              = true
  hard_expiry                  = true
  max_password_age             = 12
  password_reuse_prevention    = 5
  max_login_attempts           = 3
}

References