All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Palo Alto Networks Core Crypto Module

Certificate#4741StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorPalo Alto Networks, Inc.
Low review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/25/2029
CaveatInterim validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy
VendorPalo Alto Networks, Inc.

Approved Algorithms (55)

AlgorithmACVP Cert
AES-CBCA4206
AES-CBCA4207
AES-GCMA4206
AES-GCMA4207
Conditioning Component AES-CBC-MAC SP800-90BA1791
Conditioning Component AES-CBC-MAC SP800-90BA2138
Conditioning Component AES-CBC-MAC SP800-90BA2153
Conditioning Component AES-CBC-MAC SP800-90BA2165
Conditioning Component AES-CBC-MAC SP800-90BA2518
Conditioning Component AES-CBC-MAC SP800-90BA2541
Counter DRBGA4206
Counter DRBGA4207
ECDSA KeyGen (FIPS186-4)A4206
ECDSA KeyGen (FIPS186-4)A4207
ECDSA KeyVer (FIPS186-4)A4206
ECDSA KeyVer (FIPS186-4)A4207
ECDSA SigGen (FIPS186-4)A4206
ECDSA SigGen (FIPS186-4)A4207
ECDSA SigVer (FIPS186-4)A4206
ECDSA SigVer (FIPS186-4)A4207
HMAC-SHA-1A4206
HMAC-SHA-1A4207
HMAC-SHA2-224A4206
HMAC-SHA2-224A4207
HMAC-SHA2-256A4206
HMAC-SHA2-256A4207
HMAC-SHA2-384A4206
HMAC-SHA2-384A4207
HMAC-SHA2-512A4206
HMAC-SHA2-512A4207
KAS-ECC-SSC Sp800-56Ar3A4206
KAS-ECC-SSC Sp800-56Ar3A4207
KAS-FFC-SSC Sp800-56Ar3A4206
KAS-FFC-SSC Sp800-56Ar3A4207
RSA KeyGen (FIPS186-4)A4206
RSA SigGen (FIPS186-4)A4206
RSA SigGen (FIPS186-4)A4207
RSA SigVer (FIPS186-4)A4206
RSA SigVer (FIPS186-4)A4207
Safe Primes Key GenerationA4206
Safe Primes Key GenerationA4207
Safe Primes Key VerificationA4206
Safe Primes Key VerificationA4207
SHA-1A4206
SHA-1A4207
SHA2-224A4206
SHA2-224A4207
SHA2-256A4206
SHA2-256A4207
SHA2-384A4206
SHA2-384A4207
SHA2-512A4206
SHA2-512A4207
TLS v1.2 KDF RFC7627A4206
TLS v1.2 KDF RFC7627A4207

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Palo Alto Networks Core Crypto Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Self-test<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Palo Alto Networks Core Crypto Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Self-test<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Palo Alto Networks Core Crypto Module Version: 1.7 Revision Date: July 23, 2025 Palo Alto Networks, Inc.​ www.paloaltonetworks.com​ © 2025 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies. ​

Page 2
Table of Contents
#SectionPage
Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, Authentication1
5Software / Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-Invasive SecurityN/A
9Sensitive Security Parameter Management1
10Self-Tests1
11Life-Cycle Assurance1
12Mitigation of Other AttacksN/A

The table below provides the security levels of the various sections of FIPS 140-3 in relation to the Palo Alto Networks Core Crypto Module (hereafter referred to as the Module). Table 1 - Security Levels The Palo Alto Networks Core Crypto Module is a software cryptographic module that can run on various environments. The module is designed to run on various hardware devices (multi-chip standalone embodiment) and contains a cryptographic boundary. The cryptographic boundary includes all of the logical software components of the module. The physical perimeter is defined by the enclosure around the hardware on which it runs. See below for more details regarding the platforms. Once initialized, the module provides only an Approved mode of operation that only includes Approved algorithms and key sizes. There is no mechanism to enable non-Approved algorithms or functions. The module is built into PAN-OS/Panorama/WildFire 10.2,11.0, 11.1 and 11.2. It is delivered with the respective Device OS. There is no standalone delivery of the module as a software library. The vendor’s internal development process guarantees that the correct version of the module goes with its intended OS. The Module’s software version for this validation is 1.0 or 1.1 (see note under table 2) and is defined as a software cryptographic module

Page 4
#Operating SystemHardware PlatformProcessorPAA/Acceler ation
1PAN-OS 10.2PA-410Intel Denverton C3436LN/A
2PAN-OS 11.0PA-410Intel Denverton C3436LN/A
3PAN-OS 11.0PA-415Intel Denverton C3436LN/A
4PAN-OS 10.2PA-440Intel Denverton C3558RN/A
5PAN-OS 11.0PA-440Intel Denverton C3558RN/A
6PAN-OS 11.0PA-445Intel Denverton C3558RN/A
7PAN-OS 10.2PA-450Intel Denverton C3758RN/A
8PAN-OS 11.0PA-450Intel Denverton C3758RN/A
9PAN-OS 10.2PA-460Intel Denverton C3758RN/A
10PAN-OS 11.0PA-460Intel Denverton C3758RN/A
11PAN-OS 10.2PA-220Marvell CN7130N/A
12PAN-OS 10.2PA-220RMarvell CN7130N/A
13PAN-OS 10.2PA-820Marvell CN7240N/A
14PAN-OS 11.0PA-820Marvell CN7240N/A
15PAN-OS 10.2PA-850Marvell CN7240N/A
16PAN-OS 11.0PA-850Marvell CN7240N/A
17PAN-OS 11.0PA-1410Intel Atom C5325N/A
18PAN-OS 11.0PA-1420Intel Atom C5325C1N/A
19PAN-OS 10.2PA-3410Intel Atom P5332N/A
20PAN-OS 11.0PA-3410Intel Atom P5332N/A
21PAN-OS 10.2PA-3420Intel Atom P5342N/A
22PAN-OS 11.0PA-3420Intel Atom P5342N/A
23PAN-OS 10.2PA-3430Intel Atom P5352N/A
24PAN-OS 11.0PA-3430Intel Atom P5352N/A
25PAN-OS 10.2PA-3440Intel Atom P5362N/A
26PAN-OS 11.0PA-3440Intel Atom P5362N/A
27PAN-OS 10.2PA-5410AMD EPYC 7352N/A
28PAN-OS 11.0PA-5410AMD EPYC 7352N/A
29PAN-OS 10.2PA-5420AMD EPYC 7452N/A
30PAN-OS 11.0PA-5420AMD EPYC 7452N/A
31PAN-OS 10.2PA-5430AMD EPYC 7642N/A
32PAN-OS 11.0PA-5430AMD EPYC 7642N/A
33PAN-OS 11.0PA-5440AMD EPYC 7742N/A
34PAN-OS 10.2PA-5450Intel Xeon D-2187NTN/A

Non-Compliant State Failure to follow the directions in the Approved Mode of Operation above and Section 11 will result in the module operating in a non-compliant state. Note: For Operational Environments which use Panorama or WildFire as the Operating System in Table 2, algorithms from A4207 are not supported. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 4

Page 5
35PAN-OS 11.0PA-5450Intel Xeon D-2187NTN/A
36PAN-OS 10.2PA-3220Intel Pentium D1517 / CN7350N/A
37PAN-OS 11.0PA-3220Intel Pentium D1517 / CN7350N/A
38PAN-OS 10.2PA-3250Intel Pentium D1517 / CN7350N/A
39PAN-OS 11.0PA-3250Intel Pentium D1517 / CN7350N/A
40PAN-OS 10.2PA-3260Intel Pentium D1517 / CN7360N/A
41PAN-OS 11.0PA-3260Intel Pentium D1517 / CN7360N/A
42PAN-OS 10.2PA-5220Intel Xeon D-1548 / CN7885N/A
43PAN-OS 11.0PA-5220Intel Xeon D-1548 / CN7885N/A
44PAN-OS 10.2PA-5250Intel Xeon D-1567 / CN7890N/A
45PAN-OS 11.0PA-5250Intel Xeon D-1567 / CN7890N/A
46PAN-OS 10.2PA-5260Intel Xeon D-1567 / CN7890N/A
47PAN-OS 11.0PA-5260Intel Xeon D-1567 / CN7890N/A
48PAN-OS 10.2PA-5280Intel Xeon D-1567 / CN7890N/A
49PAN-OS 11.0PA-5280Intel Xeon D-1567 / CN7890N/A
50PAN-OS 10.2PA-7050Intel Xeon D-1567 / CN7890N/A
51PAN-OS 11.0PA-7050Intel Xeon D-1567 / CN7890N/A
52PAN-OS 10.2PA-7080Intel Xeon D-1567 / CN7890N/A
53PAN-OS 11.0PA-7080Intel Xeon D-1567 / CN7890N/A
54Panorama 10.2M-200Intel Xeon E5-2620 V4N/A
55Panorama 11.0M-200Intel Xeon E5-2620 V4N/A
56Panorama 10.2M-300Intel Xeon 4310N/A
57Panorama 11.0M-300Intel Xeon 4310N/A
58Panorama 10.2M-600Intel Xeon E5-2680 V4N/A
59Panorama 11.0M-600Intel Xeon E5-2680 V4N/A
60Panorama 10.2M-700Intel Xeon 4316N/A
61Panorama 11.0M-700Intel Xeon 4316N/A
62WildFire 10.2WF-500Intel Xeon E5-2620N/A
63WildFire 11.0WF-500Intel Xeon E5-2620N/A
64WildFire 10.2WF-500-BIntel Xeon 4316N/A
65WildFire 11.0WF-500-BIntel Xeon 4316N/A
66PAN-OS 10.2 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
67PAN-OS 11.0 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
68PAN-OS 10.2 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
69PAN-OS 11.0 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A

© 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 5

Page 6
70PAN-OS 10.2 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
71PAN-OS 11.0 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
72Panorama 10.2 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
73Panorama 11.0 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
74Panorama 10.2 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
75Panorama 11.0 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
76Panorama 10.2 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
77Panorama 11.0 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
78PAN-OS 11.1PA-460Intel Denverton C3758RN/A
79PAN-OS 11.2PA-460Intel Denverton C3758RN/A
80PAN-OS 11.1PA-850Marvell CN7240N/A
81PAN-OS 11.1PA-1410Intel Atom C5325N/A
82PAN-OS 11.2PA-1410Intel Atom C5325N/A
83PAN-OS 11.1PA-3250Intel Pentium D1517 / CN7350N/A
84PAN-OS 11.1PA-3410Intel Atom P5332N/A
85PAN-OS 11.2PA-3410Intel Atom P5332N/A
86PAN-OS 11.1PA-5250Intel Xeon D-1567 / CN7890N/A
87PAN-OS 11.2PA-5250Intel Xeon D-1567 / CN7890N/A
88PAN-OS 11.1PA-5410AMD EPYC 7352N/A
89PAN-OS 11.2PA-5410AMD EPYC 7352N/A
90PAN-OS 11.1PA-5440AMD EPYC 7742N/A
91PAN-OS 11.2PA-5440AMD EPYC 7742N/A
92PAN-OS 11.1PA-5450Intel Xeon D-2187NTN/A
93PAN-OS 11.2PA-5450Intel Xeon D-2187NTN/A
94PAN-OS 11.1PA-7080Intel Xeon D-1567 / CN7890N/A
95PAN-OS 11.2PA-7080Intel Xeon D-1567 / CN7890N/A
96PAN-OS 11.1PA-7500Intel Atom P5752 Intel Xeon D-2798NX Intel Denverton C3758RN/A
97Panorama 11.1M-200Intel Xeon E5-2620 V4N/A
98Panorama 11.2M-200Intel Xeon E5-2620 V4N/A
99Panorama 11.1M-300Intel Xeon 4310N/A
100Panorama 11.2M-300Intel Xeon 4310N/A
101Panorama 11.1M-600Intel Xeon E5-2680 V4N/A
102Panorama 11.2M-600Intel Xeon E5-2680 V4N/A
103Panorama 11.1M-700Intel Xeon 4316N/A

© 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 6

Page 7
104Panorama 11.2M-700Intel Xeon 4316N/A
105WildFire 11.1WF-500Intel Xeon E5-2620N/A
106WildFire 11.2WF-500Intel Xeon E5-2620N/A
107WildFire 11.1WF-500-BIntel Xeon 4316N/A
108WildFire 11.2WF-500-BIntel Xeon 4316N/A
109PAN-OS 11.1 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
110PAN-OS 11.2 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
111PAN-OS 11.1 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
112PAN-OS 11.2 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
113PAN-OS 11.1 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
114PAN-OS 11.2 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
115Panorama 11.1 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
116Panorama 11.2 with VMware ESXi v7.0Dell PowerEdge R740Intel Gold 6248N/A
117Panorama 11.1 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
118Panorama 11.2 with Microsoft Hyper-V Server 2019Dell PowerEdge R740Intel Gold 6248N/A
119Panorama 11.1 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
120Panorama 11.2 with KVM on Ubuntu 20.04Dell PowerEdge R740Intel Gold 6248N/A
#Operating SystemHardware Platform
1PAN-OS VM-Series or Panorama Virtual Appliance 10.2, 11.0, 11.1, or 11.2 on Amazon Web Services (AWS)x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system)
2PAN-OS VM-Series or Panorama Virtual Appliance 10.2, 11.0, 11.1, or 11.2 on Microsoft Azure
3PAN-OS VM-Series or Panorama Virtual Appliance 10.2, 11.0, 11.1, or 11.2 on Google Cloud Platform (GCP)
4PAN-OS 11.1 or PAN-OS 11.2PA-410, PA-410R, PA-410R-5G, PA-415, PA-415-5G, PA-440, PA-445,

Table 2 - Tested Operational Environments Note: Operational Environments #27-33 and #88 - 91 in Table 2 were tested using software version 1.1 of the module. All other OE’s were tested using version 1.0 of the module. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 7

Page 8
PA-450PA-450R, PA-450R-5G, PA-455, PA-455-5G
5PAN-OS 11.1PA-820
6PAN-OS 11.1 or PAN-OS 11.2PA-1420
7PAN-OS 11.1 or PAN-OS 11.2PA-3420, PA-3430, PA-3440
8PAN-OS 11.1 or PAN-OS 11.2PA-5420, PA-5430, PA-5445
9PAN-OS 11.1PA-3220, PA-3260
10PAN-OS 11.1 or PAN-OS 11.2PA-5220, PA-5260, PA-5280
11PAN-OS 11.1 or PAN-OS 11.2PA-7050
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A1791Conditioning Component AES-CBC-MAC SP 800-90BAES-CBC-MAC128 bitsVetted conditioning component for ESV Cert. #E69
A2138Vetted conditioning component for ESV Cert. #E70
A2153Vetted conditioning component for ESV Cert. #E68
A2165Vetted conditioning component for ESV Cert. #E65, E66, E72, E73
A2518Vetted conditioning component for ESV Cert. #E64, E162
A2541Vetted conditioning component for ESV Cert. #E71
A4206, A4207AES-CBC [SP 800-38A]CBC128, 192 and 256 bitsEncryption Decryption
A4206, A4207AES-GCM [SP 800-38D]GCM128 and 256 bits Note: 192 tested, but not usedEncryption Decryption
A4206, A4207Counter DRBG [SP 800-90Arev1]CTR DRBGAES 256 bits with Derivation Function EnabledRandom Bit Generator
A4206, A4207ECDSA KeyGen (FIPS 186-4)ECDSA KeyGenP-256, P-384, P-521Key Generation
A4206, A4207ECDSA KeyVer (FIPS 186-4)ECDSA KeyVerP-256, P-384, P-521Public Key Validation
A4206, A4207ECDSA SigGen (FIPS 186-4)ECDSA SigGenP-256, P-384, P-521 with SHA2-224, SHA2-256, SHA2-384, and SHA2-512Signature Generation
A4206, A4207ECDSA SigVer (FIPS 186-4)ECDSA SigVerP-256, P-384, P-521 with SHA-1, SHA2-224, SHA2-256, SHA2-384, and SHA2-512Signature Verification

Table 3 - Vendor Affirmed Operational Environments The cryptographic modules support the following Approved algorithms. Only the algorithms, modes, and key sizes specified in this table are used by the module. The CAVP certificate may contain more tested options than listed in this table. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 8

Page 9
A4206, A4207HMAC-SHA-1 [FIPS 198-1]HMACHMAC-SHA-1 with λ=96, 160Authentication for protocols
A4206, A4207HMAC-SHA2-224 [FIPS 198-1]HMACHMAC-SHA2-224 with λ=224Authentication for protocols
A4206, A4207HMAC-SHA2-256 [FIPS 198-1]HMACHMAC-SHA2-256 with λ=256Authentication for protocols
A4206, A4207HMAC-SHA2-384 [FIPS 198-1]HMACHMAC-SHA2-384 with λ=384Authentication for protocols
A4206, A4207HMAC-SHA2-512 [FIPS 198-1]HMACHMAC-SHA2-512 with λ=512Authentication for protocols
A4206, A4207KAS-ECC-SSC Sp800-56Ar3KASephemeralUnified: P-256/P-384/P-521Key Exchange
A4206, A4207KAS-FFC-SSC SP 800-56Ar3KASdhEphem: MODP-2048/3072/4096Key Exchange
A4206RSA KeyGen (FIPS 186-4)RSA KeyGen (FIPS 186-4)2048, 3072, and 4096 bitsKey Pair Generation
A4206, A4207RSA SigGen (FIPS 186-4)RSA SigGen (FIPS 186-4)2048, 3072, and 4096-bit with hashes SHA2-256/384/512Signature Generation
A4206, A4207RSA SigVer (FIPS 186-4)RSA SigVer (FIPS 186-4)2048, 3072, 4096-bit (per IG C.F) with hashes SHA-1/SHA2-224+++/256/384/512 (Signature Verification) +++ This Hash algorithm is not supported for ANSI X9.31Signature Verification
A4206, A4207SHA-1 [FIPS 180-4]SHASHA-1Digital Signature Generation/Verification Non-Digital Signature Applications (e.g. component of HMAC)
A4206, A4207SHA2-224 [FIPS 180-4]SHA2SHA-224Digital Signature Generation/Verification Non-Digital Signature Applications (e.g. component of HMAC)
A4206, A4207SHA2-256 [FIPS 180-4]SHA2SHA-256Digital Signature Generation/Verification Non-Digital Signature Applications (e.g. component of HMAC)
A4206, A4207SHA2-384 [FIPS 180-4]SHA2SHA-384Digital Signature Generation/Verification Non-Digital Signature Applications (e.g. component of HMAC)
A4206, A4207SHA2-512 [FIPS 180-4]SHA2SHA-512Digital Signature Generation/Verification Non-Digital Signature Applications (e.g. component of HMAC)
A4206, A4207Safe Primes Key Generation [RFC 3526]Safe Primes Key GenerationMODP-2048/3072/4096Safe Primes Key Generation
A4206, A4207Safe Primes Key Verification [RFC 3526]Safe Primes Key VerificationMODP-2048/3072/4096Safe Primes Key Verification

© 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 9

Page 10
A4206, A4207TLS v1.2 KDF RFC7627 (CVL)TLS v1.2 KDF RFC7627TLS v1.2 Hash Algorithm: SHA2-256, SHA2-384TLS
AES Cert. #A4206 and HMAC Cert. #A4206KTS [SP 800-38F]SP 800-38A, FIPS 198-1, and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.AES-CBC plus HMAC 128 or 256-bit keys providing 128 or 256 bits of encryption strengthKey Wrapping
AES Cert. #A4207 and HMAC Cert. #A4207KTS [SP 800-38F]SP 800-38A, FIPS 198-1, and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.AES-CBC plus HMAC 128 or 256-bit keys providing 128 or 256 bits of encryption strengthKey Wrapping
AES-GCM Cert. #A4206KTS [SP 800-38F]SP 800-38D and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.AES-GCM 128 and 256-bit keys providing 128 or 256 bits of encryption strengthKey Wrapping
AES-GCM Cert. #A4207KTS [SP 800-38F]SP 800-38D and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.AES-GCM 128 and 256-bit keys providing 128 or 256 bits of encryption strengthKey Wrapping
ESV Cert. #E27SP 800-90BESVAMD Random Number GeneratorEntropy
ESV Cert. #E64Palo Alto Networks DRNG Entropy Source
ESV Cert. #E65Palo Alto Networks DRNG Entropy Source
ESV Cert. #E66Palo Alto Networks DRNG Entropy Source
ESV Cert. #E68Palo Alto Networks DRNG Entropy Source
ESV Cert. #E69Palo Alto Networks DRNG Entropy Source
ESV Cert. #E70Palo Alto Networks DRNG Entropy Source
ESV Cert. #E71Palo Alto Networks DRNG Entropy Source
ESV Cert. #E72Palo Alto Networks DRNG Entropy Source
ESV Cert. #E73Palo Alto Networks DRNG Entropy Source
ESV Cert. #E128Octeon III Entropy Source
ESV Cert. #E130Palo Alto Networks RTC Entropy Source
ESV Cert, #E162Palo Alto Networks DRNG Entropy Source
KAS-ECC-SSC Cert. #A4206, TLS v1.2 KDF RFC7627 Cert. #A4206KAS [SP 800-56Arev3]SP 800-56Arev3. KAS-ECC per IG D.F Scenario 2 path (2).P-256, P-384, and P-521 curves providing 128, 192, or 256 bits of encryption strengthKey Exchange with protocol KDF
KAS-ECC-SSC Cert. #A4207, TLS v1.2 KDFKAS [SP 800-56Arev3]SP 800-56Arev3. KAS-ECC per IGP-256, P-384, and P-521 curves providing 128, 192, or 256 bits of encryption strengthKey Exchange with protocol KDF

D.G. D.G. D.G. D.G. (2). © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 10

Page 11
RFC7627 Cert. #A4207D.F Scenario 2 path (2).
KAS-FFC-SSC Cert. #A4206, TLS v1.2 KDF RFC7627 Cert. #A4206KAS [SP 800-56Arev3]SP 800-56Arev3. KAS-FFC per IG D.F Scenario 2 path (2).MODP-2048/3072/4096 2048-bit to 4096-bit key providing 112 bits to 150 bits of encryption strengthKey Exchange with protocol KDF
KAS-FFC-SSC Cert. #A4207, TLS v1.2 KDF RFC7627 Cert. #A4207KAS [SP 800-56Arev3]SP 800-56Arev3. KAS-FFC per IG D.F Scenario 2 path (2).MODP-2048/3072/4096 2048-bit to 4096-bit key providing 112 bits to 150 bits of encryption strengthKey Exchange with protocol KDF
Vendor AffirmedCKG (SP 800-133rev2)Section 5.1, Section 5.2Cryptographic Key Generation; SP 800- 133 and IG D.H.Key Generation Note: The seeds used for asymmetric key pair generation are produced using the unmodified/direct output of the DRBG

(2). (2). Table 4 - Approved Algorithms The module does not have any algorithms that fall under:

Page 12

186-2 SigVer. All supported modulus sizes are CAVP testable and tested as noted above. The module does not implement RSA key transport in the approved mode. In all the above cases, the nonce_explicit is always generated deterministically. AES GCM keys are zeroized when the module is power-cycled. For each new TLS session, a new AES GCM key is established. Figure 1 - Cryptographic Boundary © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 12

Page 13

Figure 1A - Physical Perimeter © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 13

Page 14
Physical PortLogical InterfaceData that passes over port/interface
Physical ports of the tested platformStatus OutputAPI return values
Physical ports of the tested platformData InputAPI input parameters
Physical ports of the tested platformData OutputAPI output parameters and return values
Physical ports of the tested platformControl InputAPI input parameters

3. Cryptographic Module Interfaces The module is a software module and does not have any physical ports, but the hardware platform that the module executes on has physical ports. The module does not support a control output interface. Table 5 - Ports and Interfaces © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 14

Page 15
RoleServiceInputOutput
COInitializeAPI to initialize moduleStatus of initialization of module
COSelf-testAPI for running self-testStatus of the self-test results
COShow StatusAPI for show statusModule’s status information
COShow Module VersionAPI for module versionModule’s name and version
COZeroizeAPI for zeroizationStatus of zeroization
CORandom Number GenerationAPI for random number generatorRandom number provided
COAsymmetric Key GenerationAPI for asymmetric key generationModule generated asymmetric key
COSymmetric Encrypt/DecryptAPI for encrypting/decryptingModule performs encrypt/decrypting with a symmetric key
COMessage DigestAPI for message digestModule provides hash for calling application
COKeyed HashAPI for keyed hashModule provides keyed hash for calling application
COKey WrappingAPI for key wrappingModule provides key wrapping service for calling application
CODigital SignatureAPI for digital signatureModule performs digital signature functions for calling application
COCrypto ProtocolsAPI for TLS crypto protocolModule provides crypto protocol processing for calling application

4. Roles, Services, and Authentication Roles The module implements only one role, which is the Crypto Officer (CO) role. There is no User role supported. The module does not support operator authentication. The CO role is implicitly assumed by the entity accessing services implemented by the module. No further authentication is required. The module does not provide a maintenance role or bypass capability. Services The Approved services supported by the module are noted in the following table: Table 6 - Roles, Service Commands, Input and Output © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 15

Page 16
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
InitializeModule performs initialization procedures for Approved modeN/AN/ACON/AGlobal indicator (“FIPS-CC” mode) and System logs
Self-testPerforms self-tests including software integrity verificationHMAC-SHA2-256, ECDSA SigVer (FIPS 186-4)Software Integrity Verification KeyCOEGlobal indicator (“FIPS-CC” mode) and System logs
Show StatusFunction that provides module status informationN/AN/ACON/AGlobal indicator (“FIPS-CC” mode) and System logs
Show Module VersionFunction that provides the module’s name and versionN/AN/ACON/AGlobal indicator (“FIPS-CC” mode) and System logs
ZeroizeFunction that destroys all SSPsN/AAll keys and SSPsCOZZeroization indicator
Random Number GenerationUsed for random number generationCounter DRBG, ESVDRBG Seed DRBG V Entropy Input String DRBG KeyCOG/EGlobal indicator (“FIPS-CC” mode) and System logs
Asymmetric Key GenerationUsed to generate asymmetric keysCKG, Counter DRBG, ESV RSA KeyGen (FIPS 186-4) ECDSA KeyGen (FIPS 186-4)RSA Private Keys, RSA Public Keys ECDSA Private Keys, ECDSA Public Keys, CA CertificatesCOG/W/EGlobal indicator (“FIPS-CC” mode) and System logs
DRBG Seed DRBG V Entropy Input String DRBG KeyG/E
Symmetric Encrypt/DecryptUsed to encrypt/decrypt dataAES-CBC AES-GCMTLS Encryption KeysCOW/EGlobal indicator (“FIPS-CC” mode) and System logs
Message DigestUsed to generate a SHA message digestSHA2-256 SHA2-384 SHA2-512N/ACON/AGlobal indicator (“FIPS-CC” mode) and System logs
Keyed HashUsed to generate or verify data integrity with HMACHMAC-SHA2-256 HMAC-SHA2-384TLS HMAC KeysCOG/R/W/EGlobal indicator (“FIPS-CC” mode) and System logs
Key WrappingUsed to encrypt or decrypt a key value on behalf of the calling applicationKTSAES-GCMTLS Encryption KeysCOR/EGlobal indicator (“FIPS-CC” mode) and System logs
KTSAES-CBC
HMAC-SHA 2-256 HMAC-SHA 2-384TLS HMAC Keys
Digital SignatureUsed to generate or verify RSA/ECDSA digital signaturesRSA SigGenRSA Private KeysCOG/R/W/EGlobal indicator (“FIPS-CC” mode) and System logs
RSA SigVerRSA Public Keys
ECDSA SigGenECDSA Private Keys
ECDSA SigVerECDSA Public Keys

The following table defines the relationship between access to SSPs and the different module services. The module performs key generation in accordance with the applicable protocol/algorithm. The resulting generated seed used in the asymmetric key generation is the unmodified output from SP800-90A DRBG. The calling application is responsible for storage of generated keys returned by the module. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 16

Page 17
Counter DRBG, ESVDRBG Seed DRBG V Entropy Input String DRBG KeyG/EGlobal indicator (“FIPS-CC” mode) and System logs
Crypto ProtocolsUsed to support crypto protocols for TLSKAS-ECC -SSC KAS-FFC- SSCTLS v1.2 KDF RFC7627TLS Pre-Master SecretCOG/E/ZGlobal indicator (“FIPS-CC” mode) and System logs
TLS v1.2 KDF RFC7627TLS Master Secret
CKG, ECDSA KeyGen (FIPS 186-4), ECDSA KeyVer (FIPS 186-4), KAS-ECC-SS C, KAS-FFC-SS C, Safe Primes Key Generation, Safe Primes Key VerificationTLS DHE/ECDHE Private Components TLS DHE/ECDHE Public Components
KTSHMAC-SHA 2-256 HMAC-SHA 2-384TLS HMAC Keys
AES-CBCTLS Encryption Keys
KTSAES-GCM
Counter DRBG, ESVDRBG Seed DRBG V Entropy Input String DRBG KeyG/E

C, Table 7 - Approved Services G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Note: There is no table for non-Approved services as the module only supports Approved services. 5. Software/Firmware Security The module performs the Software Integrity test by using HMAC-SHA-256 (HMAC Cert. #A4206) and ECDSA signature verification (ECDSA Cert. #A4206) during the Pre-Operational Self-Test. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 17

Page 18
Key/SSP/Name/T ypeStrengthSecurity Function and Cert. NumberGenerationImport/Expo rtEstablishmentStorageZeroizationUse & Related Keys
CA Certificates112 bits minimumRSA SigVer (FIPS 186-4), ECDSA SigVer (FIPS 186-4) Cert. #A4206, A4207DRBG, FIPS 186-4Imported/Ex ported through API callsN/AHDD/RAM – plaintextHDD – Zeroize Service RAM - Zeroize at session terminationECDSA/RSA Public key - Used to trust a root CA intermediate CA and leaf /end entity certificates (RSA 2048, 3072, and 4096 bits) (ECDSA P-256, P-384, and P-521)
RSA Public Keys112 bits minimumRSA SigVer (FIPS 186-4) RSA Cert. #A4206, A4207DRBG, FIPS 186-4Imported/Ex ported through API callsN/AHDD/RAM – plaintextZeroize ServiceRSA public keys managed as certificates for the verification of signatures, establishment of TLS, operator authentication and peer authentication.
  1. Operational Environment The module will operate in a modifiable operational environment per the FIPS 140-3 definition. The operating system shall be restricted to a single operator mode of operation (i.e., concurrent operators are explicitly excluded). The external application that makes calls to the module is the single user of the module, even when the application is serving multiple clients. For a listing of tested environments, see Table 2 and Table 3 above. The module is also available in other environments besides the tested environment if the module’s show status outputs the proper name and version as noted in Section
  2. The CMVP allows user porting of a validated software module to an operational environment which was not included as part of the validation testing. An operator may install and run the Palo Alto Networks Crypto Module on any general purpose computer (GPC) or platform using the specified hypervisor and operating system on the validation certificate or other compatible operating and/or hypervisor system and affirm the modules continued FIPS 140-3 validation compliance. The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported and executed in an operational environment not listed on the validation certificate.
  3. Physical Security There are no applicable FIPS 140-3 physical security requirements as this is a software module.
  4. Non-Invasive Security No approved non-invasive attack mitigation test metrics are defined at this time.
  5. Sensitive Security Parameters The following table details all the sensitive security parameters utilized by the module. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 18
Page 19
(RSA 2048, 3072, or 4096-bit)
RSA Private Keys112 bits minimumRSA SigGen (FIPS 186-4) Cert. #A4206, A4207DRBG, FIPS 186-4Imported/Ex ported through API callsN/ARAM – plaintextHDD – Zeroize Service RAM - Zeroize at session terminationRSA Private keys for generation of signatures, authentication or key establishment. (RSA 2048, 3072, or 4096-bit)
ECDSA Public Keys128 bits minimumECDSA SigVer (FIPS 186-4) Cert. #A4206, A4207DRBG, FIPS 186-4Imported/Ex ported through API callsN/AHDD/RAM – plaintextZeroize ServiceECDSA public keys managed as certificates for the verification of signatures, establishment of TLS, operator authentication and peer authentication. (ECDSA P-256, P-384, or P-521)
ECDSA Private Keys128 bits minimumECDSA SigGen (FIPS 186-4) Cert. #A4206, A4207DRBG, FIPS 186-4Imported/Ex ported through API callsN/ARAM – plaintextHDD – Zeroize Service RAM - Zeroize at session terminationECDSA Private key for generation of signatures and authentication (P-256, P-384, or P-521)
TLS DHE/ECDHE Private Components112 bits minimumKAS-ECC-SS C, KAS-FFC-SSC Cert. #A4206, A4207DRBG, SP 800-56A Rev. 3N/AN/ARAM - plaintextZeroize at session terminationEphemeral Diffie-Hellman private FFC or EC component used in TLS (DHE 2048, ECDHE P-256, P-384, P-521)
TLS DHE/ECDHE Public Components112 bits minimumKAS-ECC-SS C, KAS-FFC-SSC Cert. #A4206, A4207DRBG, SP 800-56A Rev. 3Imported/Ex ported through API callsN/AN/AZeroize at session terminationDiffie_Hellman or EC Diffie-Hellman Ephemeral values used in key agreement (DHE 2048, ECDHE P-256, P-384, P-521)
TLS Pre-Master SecretN/ATLS v1.2 KDF RFC7627 Cert. #A4206, A4207KAS SP 800-56A Rev. 3N/ATLSRAM – plaintextZeroize at session terminationSecret value used to derive the TLS Master Secret along with client and server random nonces
TLS Master SecretN/ATLS v1.2 KDF RFC7627 Cert. #A4206, A4207TLS v1.2 KDF RFC7627N/ATLSRAM – plaintextZeroize at session terminationSecret value used to derive the TLS session keys
TLS Encryption Keys128 bits minimumAES-CBC, AES-GCM Cert. #A4206, A4207TLS v1.2 KDF RFC7627N/ATLS, KAS SP 800-56A Rev. 3RAM - plaintextZeroize at session terminationAES (128 or 256 bit) keys used in TLS connections (GCM; CBC)
TLS HMAC Keys160 bits minimumHMAC-SHA2 -256, HMAC-SHA2 -384 Cert. #A4206, A4207TLS v1.2 KDF RFC7627N/ATLS, KAS SP 800-56A Rev. 3RAM - plaintextZeroize at session terminationHMAC keys used in TLS connections (SHA-1, 256, 384) (160, 256, 384 bits)
Software Integrity Verification Key128 bitsHMAC-SHA2 -256,N/AN/AN/AHDD - plaintextN/AUsed to check the integrity of

N/A © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 19

Page 20
(not considered an SSP)ECDSA SigVer (FIPS 186-4) Cert. #A4206, A4207crypto-related code. (HMAC-SHA-256 and ECDSA P-256)
DRBG Seed384 bits (Palo Alto Networks DRNG Entropy Source) 77,598 bits (AMD Random Number Generator) 194 bits (Octeon III Entropy Source/Pal o Alto Networks RTC Entropy Source)CKG (vendor affirmed), Counter DRBG Cert. #A4206, A4207Entropy as per SP 800-90BN/ARAM - plaintextPower cycleDRBG seed coming from the entropy source Seed length = 384 bits
DRBG V128 bitsCKG (vendor affirmed), Counter DRBG Cert. #A4206, A4207Constructed as per SP 800-90AN/ARAM - plaintextPower cycleAES 256 CTR DRBG state (V) used in the generation of a random values
DRBG Key256 bitsCKG (vendor affirmed), Counter DRBG Cert. #A4206, A4207Constructed as per SP 800-90BN/ARAM - plaintextPower cycleAES 256 CTR DRBG State (Key) used in the generation of random values
Entropy Input String384 bits (Palo Alto Networks DRNG Entropy Source) 77,598 bits (AMD Random Number Generator) 194 bits (Octeon III Entropy Source/Pal o Alto Networks RTC Entropy Source)CKG (vendor affirmed), Counter DRBG Cert. #A4206, A4207Entropy as per SP 800-90BN/ARAM - plaintextPower cycleDRBG input string coming from the entropy source Input length = 384 bits

© 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 20

Page 21
Entropy SourceMinimum number of bits of entropyDetails
AMD Random Number Generator77,598 bitsESV Cert. #E27 The entropy source provides 1.31221 bits of entropy per 128-bit output. The DRBG is seeded with at least 7569408 bits of output from the entropy source. Therefore, the DRBG is seeded with at least 77,598 bits of entropy. before generating keys. [PA-5410/5420/5430/5440]
Palo Alto Networks DRNG Entropy Source384 bitsThe module uses entropy provided by the following ESV Certificates: E64, E65, E66, E68, E69, E70, E71, E72, E73, and E162. There are no configuration settings needed for this entropy source as per the ESV PUD. Source produces full entropy in the 384 bit seed.
Octeon III Entropy Source194 bitsESV Cert. #E128 The entropy source provides at least .506 bits of entropy per bit of output. The DRBG is seeded with 384-bits of output from the entropy source. Therefore the DRBG is seeded with at least 194 bits of entropy before generating keys. The module generates SSPs (e.g. keys) whose strengths are modified by available entropy. [PA-220/PA-220R/PA-800/PA-3200/PA-5200/PA-7000]
Palo Alto Networks RTC Entropy Source194 bitsESV Cert. #E130 The entropy source provides at least .5069 bits of entropy per bit of output. The DRBG is seeded with 384-bits of output from the entropy source. Therefore the DRBG is seeded with at least 194 bits of entropy before generating keys. The module generates SSPs (e.g. keys) whose strengths are modified by available entropy. [WF-500]

Table 10 - Sensitive Security Parameters Note: SSPs are implicitly zeroized when power is lost, or explicitly zeroized by the zeroize service. In the case of implicit zeroization, the SSPs are implicitly overwritten with random values due to their ephemeral memory being reset upon power loss. For the zeroization service and zeroization at session termination, the SSP's memory location is overwritten with random values. Table 11 - Non-Deterministic Random Number Generation Specification Note: These entropy sources are provided by the platforms themselves listed in Table 2 and Table 3, which are external to the module itself. © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 21

Page 22
AlgorithmSelf-Test Details
Software Integrity TestHMAC-SHA-256 Digital signature verification using ECDSA P-256 Note: The ECDSA and HMAC-SHA-256 KATs are performed prior to the Software integrity test
AlgorithmSelf-Test Details
AESKAT using AES ECB 128 bits (Encrypt) Note: Only used for satisfying self-test requirements.
AESKAT using AES ECB 128 bits (Decrypt) Note: Only used for self-test.
AESKAT using AES CMAC 128 bits (Self-tested, but not used)
AES GCMKAT using AES GCM 256 bits (Encrypt)
AES GCMKAT using AES GCM 256 bits (Decrypt)
DRBGKAT: CTR_DRBG (256 bits) Note: DRBG Health Tests as specified in SP800-90A Section 11.3 are performed (i.e. instantiate/generate/reseed)
ECDSAKAT using P-256, P-384, P-521 (Sign/Verify)
HMACKAT using HMAC-SHA-1/256/384/512
RSAKAT using RSA 2048 bits and SHA-256 (Sign/Verify) KAT using RSA 2048 bits with SHA-256 (Encrypt/Decrypt) (Self-tested, but not used)
SHAKAT using SHA-1/256/384/512
SP 800-56Arev3 KAS-ECC-SSCKAT using KAS-ECC-SSC (Shared Secret Computation) primitive Z value (P-256/384)
SP 800-56Arev3 KAS-FFC-SSCKAT using KAS-FFC-SSC (Shared Secret Computation) primitive Z value (2048 bits)
SP 800-135 KDFKAT for TLS 1.2 KDF

The cryptographic module automatically performs the following tests below when the module is loaded (i.e. at power on or reboot). The operator can command the module to perform the pre-operational and cryptographic algorithm self-tests by cycling power of the module; these tests do not require any additional operator action. Table 12 - Pre-Operational Self-Test Table 13 - Conditional Cryptographic Algorithm Self-Tests © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 22

Page 23
AlgorithmSelf-Test Details
ECDSAECDSA Pair-Wise Consistency Test (PCT)
RSARSA Pair-Wise Consistency Test (PCT)
AlgorithmSelf-Test Details
SP 800-56Arev3 KAS-ECC-SSC /KAS-FFC-SSCSP 800-56Arev3 Assurance Tests based on Sections 5.5.2, 5.6.2, and 5.6.3
Cause of ErrorError State Indicator
Conditional Cryptographic Algorithm Self-Test or Software Integrity Test FailureFIPS-CC mode failure. <Algorithm test> failed.
Conditional Pairwise Consistency or Critical Functions Test FailureSystem log prints an error message.

Table 15 - Conditional Critical Function Tests Error Handling In the event of a conditional test failure, the module will output a description of the error. These are summarized below. Table 16 - Errors and Indicators

  1. Life-Cycle Assurance The module is provided directly to solution developers, and is not directly available for the general public to download. The Palo Alto Networks Core Crypto Module is not distributed as a standalone library, and can only be used in conjunction with the platforms listed in Table 2 and Table
  2. For details regarding secure installation, initialization, startup, and operation of the module, see below. The steps below are required to place the module in a compliant state. Failure to do so will result in the module operating in a non-compliant state. Secure Operation The module is initialized via the following procedure: 1.​ During the initial boot-up, break the boot sequence by entering “maint” to access the main menu a.​ Note: PAN-OS / Panorama / WildFire version 10.2, 11.0, 11.1, or 11.2 is required to access APIs of the module 2.​ Select “Continue” 3.​ Select “Set FIPS-CC Mode” option to enter “FIPS-CC” mode (i.e. Approved mode) 5.​ When prompted, select “Reboot” and the module will re-initialize and continue into “FIPS-CC” mode a.​ The module will perform all necessary self-tests as part of initialization © 2025 Palo Alto Networks, Inc. Palo Alto Networks Core Crypto Module Security Policy 23
Page 24

6.​ The module will provide a status output indicator via the PAN-OS/Panorama/WildFire API that queries the module, and provide the following: a.​ “FIPS-CC Failure”: In event of an initialization failure, the module will provide this output b.​ “FIPS-CC mode enabled successfully”: Module provides this output if initialization is successful The module’s show status can be seen by initiating the following command, which provides the name of the module and version: