What does ETSI EN 303 645 require for default passwords?
Provision 5.1-1 applies where passwords authenticate users against the device or provide . In every state other than , all device passwords must be unique per device or defined by the user. A universal value such as "admin" cannot remain usable as an operational password after initialization.
The standard permits unique pre-installed passwords, a user-selected password during initialization, or another authentication method that does not use passwords. Standard pairing codes are not treated as machine-to-machine passwords. V3.1.3 separately recommends that passwords not be used for and requires applicable authentication mechanisms to use best-practice cryptography.
Apply the test to every password-bearing path. Check local administration, remote APIs, network protocols, companion-app handoffs, service credentials used by the device, initialization, recovery, and factory reset. Record which state each credential is usable in and whether reset restores a unique value or forces a user-defined value before normal operation.
- List every user and mechanism, including device interfaces, companion apps, local APIs, and network protocols.
- For each mechanism, state whether the password is user-defined, unique per device, factory-default only, or not used.
- Do not present a product as aligned with provision 5.1 if a universal password remains usable after initialization or reset into an operational state.
Current ETSI source for unique or user-defined passwords outside factory default, machine-to-machine password guidance, authentication cryptography, change mechanisms, and brute-force protection.
Assessment source for documenting and testing password-based authentication mechanisms in IXIT 1-AuthMech.