AWS AmazonRDS: Clarified password validation async behavior
Summary
Added documentation explaining asynchronous password validation and error handling when policies aren't met.
Security assessment
Documents security feature behavior where invalid passwords are rejected post-request, maintaining existing credentials.
Evidence
Amazon RDS then processes the request asynchronously. It updates the password in your MariaDB DB instance only if the password meets your defined policies.
Diff
diff --git a/AmazonRDS/latest/UserGuide/MariaDB.Concepts.PasswordValidationPlugins.md b/AmazonRDS/latest/UserGuide/MariaDB.Concepts.PasswordValidationPlugins.md index 65fd494cb..573eb13f9 100644 --- a//AmazonRDS/latest/UserGuide/MariaDB.Concepts.PasswordValidationPlugins.md +++ b//AmazonRDS/latest/UserGuide/MariaDB.Concepts.PasswordValidationPlugins.md @@ -23,0 +24,10 @@ For information about setting the values of parameters in parameter groups, see +After enabling the plugin, reset existing passwords to comply with your new validation policies. + +Your MariaDB DB instance handles password validation for Amazon RDS. To change a password, you first submit a password update request through the AWS Management Console, `modify-db-instance` AWS CLI command, or `ModifyDBInstance` API operation. Amazon RDS initially accepts your request, even if the password doesn't meet your policies. Amazon RDS then processes the request asynchronously. It updates the password in your MariaDB DB instance only if the password meets your defined policies. If the password doesn't meet these policies, Amazon RDS keeps the existing password and logs an error event. + + + Unable to reset your password. Error information: Password failed to meet validation rules. + + +For more information about Amazon RDS events, see [Working with Amazon RDS event notification](./USER_Events.html). +