IAMユーザーの初期パスワード設定の確認

十分に長い初期パスワードを生成し、初回サインイン時に変更を求めてください。

説明

ログインプロファイルのpassword_lengthは、生成する初期パスワードの長さを指定します。password_reset_requiredで初回サインイン時の変更を要求できます。これらはアカウント全体のパスワードポリシーとは別の設定です。

想定される影響

十分に保護されていない初期パスワードを使い続けると、発行や受け渡しの際に漏れた認証情報が悪用されるおそれがあります。

対処方法

組織の基準に合う十分な長さを指定し、password_reset_required = trueを設定してください。その後のパスワードの基準は、IAMアカウントのパスワードポリシーで管理してください。

例

以下は、初期パスワードを13文字から15文字に増やし、変更を要求する例です。実際のユーザーと受信者の公開キーは別途用意してください。

変更前

hcl
resource "aws_iam_user_login_profile" "example" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"

  password_reset_required = false
  password_length         = 13
}

変更後

hcl
resource "aws_iam_user_login_profile" "example" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"

  password_reset_required = true
  password_length         = 15
}

参考資料