Symptom
Old tutorials say "log in with pi / raspberry". On a freshly flashed Raspberry Pi OS image that fails, and a headless Pi without a screen seems unreachable.
Why
With the April 2022 Raspberry Pi OS (Bullseye) release, the default pi user was removed. A user is now created at first boot (desktop wizard, or text prompts on Lite), or preconfigured before the first boot. Existing installations kept their pi account.
Option 1: Raspberry Pi Imager (recommended)
In Imager, after choosing device and OS, use the Customisation tab:
- Hostname: unique per device (e.g.
gw-kitchen-01). - Localisation: this also sets the Wi-Fi regulatory domain.
- User: username and password (lowercase letters, digits,
_,-). - Wi-Fi: SSID and password. For a headless device this is essential, because it must be online at first boot. Enable Hidden SSID if the network doesn't broadcast.
- Remote access: enable SSH, preferably with public-key authentication instead of a password.
Then write the card and boot. Find the device by hostname (ssh user@gw-kitchen-01.local) or in the router's DHCP list.
Option 2: files on the boot partition
For scripted provisioning of many cards:
# on the boot partition of the freshly written card
touch ssh # enable SSH at next boot
echo "admin:$(openssl passwd -6)" > userconf.txt # username:encrypted-password
The April 2022 announcement describes userconf / userconf.txt with a single username:encrypted-password line. Wi-Fi also needs configuring; Imager's customisation is simpler and handles current OS versions.
Hardening for IoT gateways
- Use SSH keys and disable password login once keys work.
- One user per purpose: run services as a dedicated, non-sudo user (add it to
gpio,i2c,dialoutgroups only as needed). - Give every device its own hostname and credentials; never clone one password across a fleet.