Description
An insufficient minimum length can permit short IAM passwords that are easier to guess. Omission does not mean there is no length limit, so check the effective account policy. This policy applies to IAM user console passwords, not the root password or access keys.
Potential impact
- Short, weak passwords can be vulnerable to guessing.
- Changing the length policy does not immediately change existing passwords.
Remediation
Set minimum_password_length to meet the organization’s required password strength. The example uses 14 characters; choose the applicable standard separately. Review length and necessary character requirements, and enable MFA for console users.
Examples
These examples compare account password policies. AWS permits a custom minimum length from 6 to 128 characters.
Before
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 6
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
}
After
resource "aws_iam_account_password_policy" "example" {
minimum_password_length = 14
require_lowercase_characters = true
require_numbers = true
require_uppercase_characters = true
require_symbols = true
allow_users_to_change_password = true
}
The revision increases the minimum length from 6 to 14 characters. The new length requirement applies when users next change their passwords.