Review IAM user initial password settings

Generate a sufficiently long initial password and require a change at first sign-in.

Description

The login profile’s password_length sets the length of the initial generated password. password_reset_required can require a change at first sign-in. These settings are separate from the account-wide password policy.

Potential impact

Continuing to use an inadequately protected initial password can allow misuse of credentials exposed during creation or delivery.

Remediation

Choose a sufficient length that meets your organization’s requirements and set password_reset_required = true. Manage requirements for subsequent passwords through the IAM account password policy.

Examples

The examples increase the initial password from 13 to 15 characters and require a change. Supply the actual user and recipient’s public key separately.

Before

hcl
resource "aws_iam_user_login_profile" "example" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"

  password_reset_required = false
  password_length         = 13
}

After

hcl
resource "aws_iam_user_login_profile" "example" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"

  password_reset_required = true
  password_length         = 15
}

References