Database Account Security
Password Strength Requirements
- The password policy for database accounts created on the RDS console is as follows:
- The password consists of 8 to 32 characters.
- It must contain at least three of the following character types: uppercase letters, lowercase letters, digits, and special characters: (~ ! @ # $ % ^ * - _ = + ( ) ? ,).
- The password cannot contain the username or the username spelled backwards.
- The password policy for database accounts created on the client is controlled by the passwordcheck.rds_enable_enhanced_password_check parameter.
- This parameter is enabled by default, indicating that the password policy for accounts created on the client is the same as that on the console.
- If this parameter is disabled, the password policy for accounts created on the client is the default policy. The details are as follows:
- The password consists of at least eight characters.
- The password must contain letters and non-letter characters. Non-letter characters include digits and special characters.
- The password cannot contain the username.
SSL Encryption
SSL is enabled by default for RDS for PostgreSQL DB instances and cannot be disabled.
Suggestions for Creating Users
When you run CREATE USER or CREATE ROLE, specify a password expiration time with the VALID UNTIL 'timestamp' parameter (timestamp indicates the expiration time).
Recommendations on Accessing Database Objects
When you access a database object, specify the schema name of the database object to prevent trojan-horse attacks.
Account Description
To provide O&M services, the system automatically creates system accounts when you create RDS for PostgreSQL DB instances. These system accounts are unavailable to you.
Attempting to delete, rename, and change passwords or permissions for these accounts will result in an error.
- rdsAdmin: a management account with the highest superuser privileges. It is used to query and modify instance information, rectify faults, migrate data, and restore data.
- pg_execute_server_program: account that allows users who run the database to execute programs on the database server to cooperate with COPY and other functions that allow the execution of server programs.
- pg_read_all_settings: account that reads all configuration variables, even those that are usually visible only to the super user.
- pg_read_all_stats: account that reads all pg_stat_* views and uses various extension-related statistics, even those that are usually visible only to the super user.
- pg_stat_scan_tables: account that executes a monitoring function that may obtain an ACCESS SHARE lock on the table (and may hold the lock for a long time).
- pg_signal_backend: account that sends a signal (for example, a signal for canceling a query operation or an abortion signal) to another backend.
- pg_read_server_files: account that allows a database user to use the COPY and other file access functions to read files from any accessible directory on a server.
- pg_write_server_files: account that allows a database user to use the COPY and other file access functions to write files to any accessible directory on a server.
- pg_monitor: account that reads and executes various monitoring views and functions. It is a member of pg_read_all_settings, pg_read_all_stats, and pg_stat_scan_tables.
- rdsRepl: replication account, which is used to synchronize data from primary DB instances to standby DB instances or read replicas.
- rdsBackup: backup account, which is used for backend backup.
- rdsMetric: metric monitoring account, which is used by watchdog to collect database status data.
- __rds_pg_profile_user_: metric monitoring account, which is used by the pg_profile_pro extension to collect database status data. This account is available only for the latest version of RDS for PostgreSQL 12 and is automatically created after pg_profile_pro is created.
pg_profile_pro is not supported temporarily due to its defects. Therefore, this account will not be automatically created for new instances.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot