What does ETSI EN 303 645 require for default passwords?
Provision 5.1-1 applies where passwords are used. In any state other than factory default, each consumer IoT device password must be unique per device or defined by the user. That means a shipped value such as a universal admin password cannot be the operational password after setup.
The standard gives several acceptable patterns: unique pre-installed passwords, requiring the user to choose a password during initialization, or avoiding passwords by using another authentication method. The answer should be scoped to each authentication mechanism, not just to the product as a whole.
- List every password-based authentication mechanism for users and machine-to-machine authentication.
- For each mechanism, state whether the password is user-defined, unique per device, factory-default only, or not used.
- Do not present a product as aligned with provision 5.1 if a universal password remains usable after initialization or reset into an operational state.
Primary ETSI source for provision 5.1-1 on unique or user-defined passwords outside factory default.
Assessment source for documenting and testing password-based authentication mechanisms in IXIT 1-AuthMech.