A security team notices that some Vault users are authenticating with the Userpass auth method, but they want to enforce password complexity and expiration. What is the best approach?
Trap 1: Switch to token-based authentication and issue tokens with TTL.
Tokens do not address password complexity.
Trap 2: Use Vault's password policy plugin with Userpass.
No such plugin exists.
Trap 3: Configure password policies in Vault's Userpass auth method.
Vault's Userpass does not support password policies.
- A
Migrate users to an external identity provider and use LDAP or OIDC auth.
Userpass cannot enforce password complexity or expiration natively, so migrating users to an external identity provider via LDAP or OIDC delegates those controls to a system designed for credential lifecycle management, satisfying the stem's enforcement requirement.
- B
Switch to token-based authentication and issue tokens with TTL.
Why it fails: Tokens do not address password complexity.
- C
Use Vault's password policy plugin with Userpass.
Why it fails: No such plugin exists.
- D
Configure password policies in Vault's Userpass auth method.
Why it fails: Vault's Userpass does not support password policies.