Skip to content

Files

Latest commit

 

History

History
31 lines (22 loc) · 694 Bytes

aws-iam-set-minimum-password-length.md

File metadata and controls

31 lines (22 loc) · 694 Bytes

Pattern: Allowed short passwords for AWS IAM policy

Issue: -

Description

IAM account password policies should ensure that passwords have a minimum length. The account password policy should be set to enforce minimum password length of at least 14 characters.

Resolution: Enforce longer, more complex passwords in the policy.

Examples

Example of incorrect code:

resource "aws_iam_account_password_policy" "bad_example" {
	# ...
	# minimum_password_length not set
	# ...
}

Example of correct code:

resource "aws_iam_account_password_policy" "good_example" {
	# ...
	minimum_password_length = 14
	# ...
}