used, these shall be
generated
with
a
mechanism that reduces
the risk of automated
attacks against a class or
type of device.
1. How the pre-installed passwords
are generated for each device
and what is done to ensure that
the pre-installed passwords are
sufficiently random.
2. Where and when are the
passwords generated (e.g. offdevice and provisioned onto the
device
subsequently,
or
generated upon device's initial
boot-up sequence)?
3. How
are
the
randomised
passwords generated? Was a
random
function
or
a
cryptographically secure pseudo
random number generator used?
Are the randomised passwords
based on any device information
(MAC address, etc.)?
Minimally, the following are required for
pre-installed passwords:
1.
Passwords with incremental
counters
("password1",
"password2") are not allowed.
2.
Pre-installed passwords must
CLS Publication #2 | Page 22 of 49