Description
With require_symbols = false, RAM console passwords can omit special characters. Enable this setting when the organization requires symbols.
Potential impact
Accepted passwords may not match the character policy. Adding one symbol to a common word does not by itself make the password hard to guess.
Remediation
Set require_symbols = true when required and use sufficiently long, unpredictable passwords.
Examples
The examples enable the symbol requirement. Other values provide comparison context and are not a complete recommended configuration.
Before
hcl
resource "alicloud_ram_account_password_policy" "corporate" {
minimum_password_length = 9
require_lowercase_characters = false
require_uppercase_characters = false
require_numbers = false
require_symbols = false
hard_expiry = true
max_password_age = 12
password_reuse_prevention = 5
max_login_attempts = 3
}
After
hcl
resource "alicloud_ram_account_password_policy" "corporate" {
minimum_password_length = 9
require_lowercase_characters = false
require_uppercase_characters = false
require_numbers = false
require_symbols = true
hard_expiry = true
max_password_age = 12
password_reuse_prevention = 5
max_login_attempts = 3
}