Station Compliance›Equipment›Sage ENDEC
Equipment note
Default-password prompting, an HTTPS-only option and web access logging all arrived in one firmware revision. A 3644 below it has none of them — and is behind on more than this rule, because Rev 96 was already required back in March 2024.
Verified against manufacturer release notes and trade-press coverage. Reflects the rule as published August 2026.
Verified. Firmware Rev 96 for the Sage Digital ENDEC model 3644 added:
This page does not print the factory credential for the 3644. We have not verified it against manufacturer documentation, and a remembered default is exactly the kind of number that is right on most units and wrong on yours. Take it from the manual for your unit.
What is verified is more useful anyway: on Rev 96 or later, the ENDEC itself will prompt you to change any account still on a default password. Sage's own guidance is that if your ENDEC is reachable from the public internet you need a firewall, and you need non-default passwords — and that the ENDEC will warn you about the second.
Two things follow from that:
Rev 96 was separately required by March 11, 2024 for CAP prioritization and national message text handling, and it included replacement security certificates. A 3644 not yet on Rev 96 or later is behind on more than 47 CFR § 11.35(d), which is why "Sage 3644 below Rev 96" has its own line in the order we suggest working through a rack.
Sage has announced the end of manufacturing for the ENDEC model 3644. Confirm the current support status of your unit directly with Sage before assuming future firmware will be available.
That changes how you plan, not whether the unit is in scope. Record the firmware revision you are on and the date you confirmed support status, so the decision you made is on paper. The kit's compliance guide covers how to handle end-of-support equipment in your records.
We do not publish maximum password lengths where the manufacturer does not document them, because a guessed number would cause you to record compliance you do not have. The length your specific firmware revision accepts is something to determine on your own unit, in two minutes:
If the unit cannot hold 15 characters, the FCC's FAQ leaves three routes: an alternative authentication measure on the unit itself that is at least as secure as a strong password, a replacement unit, or a waiver from the Commission. Keeping it off the public internet is still essential, but it satisfies the separate segmentation requirement, not this one: the FAQ says a firewall or VPN in front of the device is not enough. An EAS box is in scope however it is managed, so turning off its web interface does not take it out of the rule either. Record which route you took in your own file.
Most networked broadcast gear offers more than one way in — web, Telnet, SSH, SNMP, a vendor application, a serial console, sometimes a front panel. These frequently keep separate credential stores. We have not verified which management paths on the 3644 share a credential and which do not, so do not assume: setting a strong web password on a unit whose other paths still accept the factory login changes nothing except your paperwork, which now says you fixed it.
List every management path your unit offers — the manual is the place to start — then verify each one separately: log in through it, confirm the new credential works, and confirm the old one does not.
The Sage ENDEC is one entry. The Program Chain Compliance Kit covers verified security behavior for DASDEC, Barix, Comrex, Tieline, Burk and Inovonics, plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed — with the inventory, port audit and short-password device records already written.