Alicloud RAM password reuse prevention is disabled

Restrict reuse of previous passwords.

Description

password_reuse_prevention is the number of recent passwords that cannot be reused. 0 disables history checks; use a value from 1 to 24 to prevent reuse.

Potential impact

Reusing an old password can make previously exposed credentials valid again.

Remediation

Set password_reuse_prevention to 1–24 according to organizational requirements. Avoid passwords also used for other services.

Examples

The examples prevent reuse of the last five passwords. A smaller value remembers fewer previous passwords.

Before

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  max_password_age   = 12
  max_login_attempts = 3
}

After

hcl
resource "alicloud_ram_account_password_policy" "corporate" {
  max_password_age          = 12
  password_reuse_prevention = 5
  max_login_attempts        = 3
}

References