Database Account Security
Password Strength Requirements
- For information about the database password strength requirements on the RDS console, see the database configuration table in Table 4.
- RDS has a password security policy for newly created database users. Passwords must:
- Consist of at least eight characters.
- Contain letters, digits, and special characters.
- Not contain the username.
Suggestions for Creating Users
When you run CREATE USER or CREATE ROLE, you are advised to specify a password expiration time with the VALID UNTIL 'timestamp' parameter (timestamp indicates the expiration time).
Suggestions for Accessing Databases
When you access a database object, you are advised to specify the schema name of the database object to prevent trojan-horse attacks.
Account Description
To provide O&M services, the system automatically creates system accounts when you create PostgreSQL DB instances. These system accounts cannot be used by users.
Attempting to delete, rename, and change passwords or permissions for these accounts will result in an error.
- rdsAdmin: indicates the management account, which has the highest superuser permission and is used to query and modify DB instance information, rectify faults, migrate data, and restore data.
- rdsRepl: indicates the replication account, which is used to synchronize data from primary DB instances to standby DB instances or read replicas.
- rdsBackup: indicates the backup account, which is used for background backup.
- rdsMetric: indicates the metric monitoring account, which is used by watchdog to collect database status data.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot