Ensure that SMTP credentials for IAM users are rotated every 90 days or less in order to decrease the likelihood of accidental exposures from code or logs and limit the time window for an attacker to exploit compromised credentials. Each OCI IAM user can have up to two SMTP credentials at a time.
SMTP credentials are an Oracle-generated username and password pair that an OCI IAM user creates to authenticate and send emails through the OCI Email Delivery service. These credentials are used by applications and clients to establish a secure connection using the Simple Mail Transfer Protocol (SMTP). In Oracle Cloud Infrastructure (OCI), SMTP credentials don't have an expiration date, which makes manual rotation essential to mitigate the risk of accidental exposure and limit the window of time an attacker can exploit compromised credentials. Regular rotation is a critical security best practice to enforce least privilege and reduce the potential impact of a leak.
Audit
To determine if your IAM user SMTP credentials are rotated on a periodic basis (i.e., every 90 days or less), perform the following operations:
Remediation / Resolution
To rotate (re-create) your outdated OCI IAM user SMTP credentials, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Working with SMTP Credentials
- Managing User Credentials
- Oracle Cloud Infrastructure CLI Documentation
- compartment list
- user list