Description
The login profile’s password_length sets the length of the initial generated password. password_reset_required can require a change at first sign-in. These settings are separate from the account-wide password policy.
Potential impact
Continuing to use an inadequately protected initial password can allow misuse of credentials exposed during creation or delivery.
Remediation
Choose a sufficient length that meets your organization’s requirements and set password_reset_required = true. Manage requirements for subsequent passwords through the IAM account password policy.
Examples
The examples increase the initial password from 13 to 15 characters and require a change. Supply the actual user and recipient’s public key separately.
Before
resource "aws_iam_user_login_profile" "example" {
user = aws_iam_user.example.name
pgp_key = "keybase:some_person_that_exists"
password_reset_required = false
password_length = 13
}
After
resource "aws_iam_user_login_profile" "example" {
user = aws_iam_user.example.name
pgp_key = "keybase:some_person_that_exists"
password_reset_required = true
password_length = 15
}