Derived Review-Risk Graph (review prompts, not findings)
flowchart LR
%% Deterministic review-risk graph for PAN-OS 11.0 VM-Series
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>self-test</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;Underlying clues
flowchart LR
%% Deterministic clue tier for PAN-OS 11.0 VM-Series
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>self-test</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Security Policy, page by page
PAN-OS 11.0 VM-Series Version: 1.1 Revision Date: June 13, 2024 Palo Alto Networks, Inc. www.paloaltonetworks.com © 2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
| ISO/IEC24759Section6. | FIPS140-3SectionTitle | SecurityLevel |
|---|
| 1 | General | 1 |
| 2 | CryptographicModuleSpecification | 1 |
| 3 | CryptographicModuleInterfaces | 1 |
| 4 | Roles,Services,andAuthentication | 3 |
| 5 | Software/FirmwareSecurity | 1 |
| 6 | OperationalEnvironment | 1 |
| 7 | PhysicalSecurity | N/A |
| 8 | Non-InvasiveSecurity | N/A |
| 9 | SensitiveSecurityParameterManagement | 1 |
| 10 | Self-Tests | 1 |
| 11 | Life-CycleAssurance | 3 |
| 12 | MitigationofOtherAttacks | N/A |
| OverallLevel | | 1 |
| OperatingSystem | HardwarePlatform | Processor | PAA/Acceleration |
|---|
| VMwareESXiv7.0 | DellPowerEdgeR740 | IntelXeonGold6248 | N/A |
| KVM4onUbuntu20.04 | DellPowerEdgeR740 | IntelXeonGold6248 | N/A |
| Hyper-V2019onMicrosoft Hyper-VServer2019 | DellPowerEdgeR740 | IntelXeonGold6248 | N/A |
The PAN-OS 11.0 VM-Series module is available in multiple capacity options. All models can be deployed as guest virtual machines on VMware ESXi, Hyper-V, and Linux server that is running the KVM (Kernel-based Virtual Machine) using a common base image distributed in a compatible hypervisor format. The PAN-OS VM-Series is the virtualized form factor of the Palo Alto Networks next-generation firewall. The VM-Series is used to protect applications/data from cyber threats using Palo Alto Networks’ next-generation firewall and advanced threat prevention features. For purposes of this validation, the exact software version of the module tested was 11.0.3-h12. The cryptographic module meets the overall requirements applicable to Level 1 security of FIPS 140-3. Table 1 - Security Levels ISO/IEC 24759 Section 6. FIPS 140-3 Section Title Security Level
Table, extracted as text (did not parse into structured rows)
2 Cryptographic Module Specification 1
3 Cryptographic Module Interfaces 1
4 Roles, Services, and Authentication 3
5 Software/Firmware Security 1
6 Operational Environment 1
7 Physical Security N/A
8 Non-Invasive Security N/A
9 Sensitive Security Parameter Management 1
11 Life-Cycle Assurance 3
12 Mitigation of Other Attacks N/A
Overall Level 1 2. Cryptographic Module Specification The tested operational environments are highlighted in Table 2. Table 2 - Tested Operational Environments Operating System Hardware Platform Processor PAA/Acceleration VMware ESXi v7.0 Dell PowerEdge R740 Intel Xeon Gold 6248 N/A KVM 4 on Ubuntu 20.04 Dell PowerEdge R740 Intel Xeon Gold 6248 N/A Hyper-V 2019 on Microsoft Dell PowerEdge R740 Intel Xeon Gold 6248 N/A Hyper-V Server 2019 © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 3
| OperatingSystem | HardwarePlatform |
|---|
| AmazonWebServices(AWS) MicrosoftAzure GoogleCloudPlatform(GCP) | x86Architecture (Note:Specificprocessor/hardwareisdependenton Instance/MachineTypeselectedforoperationsystem) |
Table 3 - Vendor Affirmed Operational Environments Operating System Hardware Platform Amazon Web Services (AWS) x86 Architecture Microsoft Azure (Note: Specific processor/hardware is dependent on Google Cloud Platform (GCP) Instance/Machine Type selected for operation system) Operator Porting Rules The CMVP allows user porting of a validated software module to an operational environment which was not included as part of the validation testing. An operator may install and run a VM-series firewall on any general purpose computer (GPC) or platform using the specified hypervisor and operating system on the validation certificate or other compatible operating and/or hypervisor system and affirm the modules continued FIPS 140-3 validation compliance. The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported and executed in an operational environment not listed on the validation certificate. Approved Mode of Operation The following procedure will put the module into the Approved mode of operation:
- During initial boot up, break the boot sequence via the console port connection (by entering “maint”) to access the main menu.
- Select “Continue.”
- Select the “Set FIPS-CC Mode” option to enter the Approved mode.
- Select “Enable FIPS-CC Mode”.
- When prompted, select “Reboot” and the module will re-initialize and continue into “FIPS-CC” mode (Approved mode).
- The module will reboot.
- In “FIPS-CC” mode, the console port is available only as a status output port.
- Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module
- Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten The module will automatically indicate the Approved mode of operation in the following manner:
- Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session.
- Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port.
- The module will display “FIPS-CC” at all times in the status bar at the bottom of the web interface. Should one or more power-up self-tests fail, the Approved mode of operation will not be achieved. Feedback will consist of:
- The module will reboot and enter a state in which the reason for the reboot can be determined.
- The module will output “FIPS-CC failure.”
- To determine which self-test caused the system to reboot into the error state, connect the console cable and follow the on-screen instructions to view the self-test output. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 4
| CAVPCert | Algorithmand Standard | Mode/Method | Description/Key Size(s)/Key Strength(s) | Use/Function |
|---|
| A1791 | ConditioningComponent AES-CBC-MACSP800-90B | AES-CBC-MAC | 128bits | Vettedconditioning componentforESVCert. #E69 |
| A3454 | AES-CBC[SP800-38A] | CBC | 128,192and256bits | Encryption Decryption |
| A3454 | AES-CFB128[SP800-38A] | CFB128 | 128bits | Encryption Decryption |
| A3454 | AES-CTR[SP800-38A] | CTR | 128,192and256bits | Encryption Decryption |
| A3454 | AES-GCM [SP800-38D] | GCM** | 128and256bits | Encryption Decryption |
| A3454 | CounterDRBG [SP800-90Arev1] | CTRDRBG | AES256bitswith DerivationFunction Enabled | RandomBitGenerator |
| A3454 | ECDSAKeyGen (FIPS186-4) | ECDSAKeyGen | P-256,P-384,P-521 | KeyGeneration |
| A3454 | ECDSAKeyVer(FIPS 186-4) | ECDSAKeyVer | P-256,P-384,P-521 | PublicKeyValidation |
| A3454 | ECDSASigGen(FIPS 186-4) | ECDSASigGen | P-256,P-384,P-521with SHA2-224,SHA2-256, SHA2-384,andSHA2-512 | SignatureGeneration |
| A3454 | ECDSASigVer(FIPS186-4) | ECDSASigVer | P-256,P-384,P-521with SHA-1,SHA2-224, | SignatureVerification |
Note: Disabling “FIPS-CC” mode causes a complete factory reset, which is described in the Zeroization section below. Non-Compliant State Failure to follow the directions in the Approved Mode of Operation above or rules noted in Section 11 will result in the module operating in a non-compliant state, which is considered out of scope of this validation. Zeroization To perform the zeroization service, follow the procedure below:
- Access the module’s CLI via SSH, and command the module to enter maintenance mode; the module will reboot
- Note: Establish a serial connection to the console port
- After reboot, select “Continue.”
- Select “Factory Reset.”
- The module will perform a zeroization, and provide the following message once complete: o “Factory Reset Status: Success” Approved and Allowed Algorithms The cryptographic modules support the following Approved algorithms. Only the algorithms, modes, and key sizes specified in this table are used by the module. The CAVP certificate may contain more tested options than listed in this table. Table 4
- Approved Algorithms Vetted conditioning Conditioning Component A1791 AES-CBC-MAC 128 bits component for ESV Cert. A3454 AES-CBC [SP 800-38A] CBC 128, 192 and 256 bits Decryption A3454 AES-CTR [SP 800-38A] CTR 128, 192 and 256 bits Decryption
128 and 256 bits
Table, extracted as text (did not parse into structured rows)
[SP 800-38D] Decryption AES 256 bits with Counter DRBG A3454 CTR DRBG Derivation Function Random Bit Generator [SP 800-90Arev1] ECDSA KeyGen Key Generation ECDSA KeyVer (FIPS Public Key Validation ECDSA SigGen (FIPS Signature Generation A3454 ECDSA SigVer (FIPS 186-4) ECDSA SigVer Signature Verification © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 5
| | | SHA2-256,SHA2-384,and SHA2-512 | |
|---|
| A3454 | HMAC-SHA-1[FIPS198-1] | HMAC | HMAC-SHA-1withλ=96, 160 | Authenticationfor protocols |
| A3454 | HMAC-SHA2-224 [FIPS198-1] | HMAC | HMAC-SHA2-224with λ=224 | Authenticationfor protocols |
| A3454 | HMAC-SHA2-256 [FIPS198-1] | HMAC | HMAC-SHA2-256with λ=256 | Authenticationfor protocols |
| A3454 | HMAC-SHA2-384 [FIPS198-1] | HMAC | HMAC-SHA2-384with λ=384 | Authenticationfor protocols |
| A3454 | HMAC-SHA2-512 [FIPS198-1] | HMAC | HMAC-SHA2-512with λ=512 | Authenticationfor protocols |
| A3454 | KAS-ECC-SSC Sp800-56Ar3 | KAS | P-256/P-384/P-521 | KeyExchange |
| A3454 | KAS-FFC-SSCSP 800-56Ar3 | KAS | MODP-2048/3072/4096 | KeyExchange |
| A3454 | KDFIKEv2[SP 800-135rev1](CVL) | IKEv2KDF | SHA2-256,SHA2-384, SHA2-512 | IKEv2 |
| A3454 | KDFSNMP[SP 800-135rev1](CVL) | SNMPv3KDF | EngineID: 80001F88043030303030 343935323630 | SNMPv3 |
| A3454 | KDFSSH[SP800-135rev1] (CVL) | SSHv2KDF | SHA-1,SHA2-256, SHA2-512 | SSH |
| A3454 | TLSv1.2KDFRFC7627 (CVL) | TLS1.2KDF | TLSv1.2HashAlgorithm: SHA2-256,SHA2-384 | TLS |
| A3454 | RSA KeyGen (FIPS186-4) | RSA KeyGen (FIPS186-4) | 2048,3072,and4096bits | KeyPairGeneration |
| A3454 | RSA SigGen (FIPS186-4) | RSA SigGen (FIPS186-4) | 2048,3072,and4096-bit withhashes256/384/512 | SignatureGeneration |
| A3454 | RSA SigVer (FIPS186-4) | RSA SigVer (FIPS186-4) | 2048,3072,4096-bit(per IGC.F)withhashes SHA-1/224+++/256/384/5 12(SignatureVerification) +++ThisHashalgorithmis notsupportedforANSI X9.31 | SignatureVerification |
| A3454 | SHA-1[FIPS180-4] | SHA | SHA-1 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g. componentofHMAC) |
| A3454 | SHA2-224[FIPS180-4] | SHA2 | SHA-224 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g. componentofHMAC) |
| A3454 | SHA2-256[FIPS180-4] | SHA2 | SHA-256 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g. componentofHMAC) |
| A3454 | SHA2-384[FIPS180-4] | SHA2 | SHA-384 | DigitalSignature Generation/Verification |
Table, extracted as text (did not parse into structured rows)
A3454 HMAC-SHA-1 with λ=96, Authentication for HMAC-SHA-1 [FIPS 198-1] HMAC [FIPS 198-1] protocols A3454 HMAC-SHA2-256 HMAC-SHA2-256 with Authentication for [FIPS 198-1] λ=256 protocols A3454 HMAC-SHA2-384 HMAC-SHA2-384 with Authentication for [FIPS 198-1] λ=384 protocols A3454 HMAC-SHA2-512 HMAC-SHA2-512 with Authentication for [FIPS 198-1] λ=512 protocols A3454 Key Exchange Engine ID: KDF SNMP [SP A3454 SSHv2 KDF SSH TLS v1.2 KDF RFC7627 TLS1.2 KDF TLS v1.2 Hash Algorithm: (FIPS 186-4) (FIPS 186-4) (FIPS 186-4) (FIPS 186-4) with hashes 256/384/512 IG C.F) with hashes (FIPS 186-4) (FIPS 186-4) +++ This Hash algorithm is not supported for ANSI Digital Signature A3454 SHA-1 [FIPS 180-4] SHA Non-Digital Signature component of HMAC) Digital Signature Non-Digital Signature component of HMAC) Digital Signature Non-Digital Signature component of HMAC) Digital Signature © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 6
| | | | Non-DigitalSignature Applications(e.g. componentofHMAC) |
|---|
| A3454 | SHA2-512[FIPS180-4] | SHA2 | SHA-512 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g. componentofHMAC) |
| A3454 | SafePrimesKey Generation[RFC3526] | SafePrimesKey Generation | MODP-2048, MODP-3072,MODP-4096 | SafePrimesKey Generation |
| A3454 | SafePrimesKey Verification[RFC3526] | SafePrimesKey Verification | MODP-2048, MODP-3072,MODP-4096 | SafePrimesKey Verification |
| AESCert.#A3454and HMACCert.#A3454 | KTS [SP800-38F] | SP800-38AandFIPS 198-1.KTS(keywrapping andunwrapping)perIG D.G. | AES-CBCorAES-CTRplus HMAC 128,192,and256-bitkeys providing128,192,or256 bitsofencryptionstrength | KeyWrapping |
| AES-GCMCert.A3454 | KTS [SP800-38F] | SP800-38DandSP 800-38F.KTS(key wrappingandunwrapping) perIGD.G. | AES-GCM 128and256-bitkeys providing128or256bits ofencryptionstrength | KeyWrapping |
| ESVCert.#E69 | SP800-90B | ESV | PaloAltoNetworksDRNG EntropySource | Entropy |
| KAS-ECC-SSCCert. #A3454,KDFIKEv2Cert. #A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-ECC perIGD.FScenario2path (2). | P-256andP-384curves providing128or192bits ofencryptionstrength | KeyExchangewith protocolKDF |
| KAS-ECC-SSCCert. #A3454,KDFSSHCert. #A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-ECC perIGD.FScenario2path (2). | P-256,P-384,andP-521 curvesproviding128,192, or256bitsofencryption strength | KeyExchangewith protocolKDF |
| KAS-ECC-SSCCert. #A3454,TLSv1.2KDF RFC7627Cert.#A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-ECC perIGD.FScenario2path (2). | P-256,P-384,andP-521 curvesproviding128,192, or256bitsofencryption strength | KeyExchangewith protocolKDF |
| KAS-FFC-SSCCert. #A3454,KDFIKEv2Cert. #A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-FFC perIGD.FScenario2path (2). | 2048,3072,and4096-bit keysproviding112,128,or 150 bitsofencryption strength | KeyExchangewith protocolKDF |
| KAS-FFC-SSCCert. #A3454,KDFSSHCert. #A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-FFC perIGD.FScenario2path (2). | 2048-bitkeyproviding112 bitsofencryptionstrength | KeyExchangewith protocolKDF |
| KAS-FFC-SSCCert. #A3454,TLSv1.2KDF RFC7627Cert.#A3454 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-FFC perIGD.FScenario2path (2). | 2048-bitkeyproviding112 bitsofencryptionstrength | KeyExchangewith protocolKDF |
| Vendor Affirmed | CKG (SP800-133rev2) | Section5.1,Section5.2 | CryptographicKey Generation;SP800- 133andIGD.H. | KeyGeneration Note:Symmetrickeysand theseedsusedfor asymmetrickeypair generationareproduced usingtheunmodified/direct outputoftheDRBG |
Table, extracted as text (did not parse into structured rows)
Non-Digital Signature component of HMAC) Digital Signature Non-Digital Signature component of HMAC) AES-CBC or AES-CTR plus SP 800-38A and FIPS HMAC Cert. #A3454 [SP 800-38F] and unwrapping) per IG D.G. bits of encryption strength SP 800-38D and SP AES-GCM [SP 800-38F] wrapping and unwrapping) providing 128 or 256 bits per IG D.G. of encryption strength Palo Alto Networks DRNG Entropy Source KAS-ECC-SSC Cert. SP 800-56Arev3. KAS-ECC P-256 and P-384 curves Key Exchange with #A3454, KDF IKEv2 Cert. KAS [SP 800-56Arev3] per IG D.F Scenario 2 path providing 128 or 192 bits protocol KDF #A3454 (2). of encryption strength #A3454, KDF SSH Cert. curves providing 128, 192, Key Exchange with KAS [SP 800-56Arev3] per IG D.F Scenario 2 path #A3454 or 256 bits of encryption protocol KDF (2). #A3454, TLS v1.2 KDF curves providing 128, 192, Key Exchange with KAS [SP 800-56Arev3] per IG D.F Scenario 2 path RFC7627 Cert. #A3454 or 256 bits of encryption protocol KDF (2). #A3454, KDF IKEv2 Cert. keys providing 112, 128, or Key Exchange with KAS [SP 800-56Arev3] per IG D.F Scenario 2 path #A3454 150 bits of encryption protocol KDF (2). KAS-FFC-SSC Cert. SP 800-56Arev3. KAS-FFC 2048-bit key providing 112 Key Exchange with #A3454, KDF SSH Cert. KAS [SP 800-56Arev3] per IG D.F Scenario 2 path bits of encryption strength protocol KDF KAS-FFC-SSC Cert. SP 800-56Arev3. KAS-FFC 2048-bit key providing 112 Key Exchange with #A3454, TLS v1.2 KDF KAS [SP 800-56Arev3] per IG D.F Scenario 2 path bits of encryption strength protocol KDF RFC7627 Cert. #A3454 (2). Note: Symmetric keys and Cryptographic Key the seeds used for Section 5.1, Section 5.2 Generation; SP 800- asymmetric key pair
133 and IG D.H. generation are produced
using the unmodified/direct output of the DRBG ● For TLS, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with SP 800-52 and in accordance with Section 4 of RFC 5288 for TLS key establishment, and ensures when the nonce_explicit © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 7
part of the IV exhausts all possible values for a given session key, that a new TLS handshake is initiated per sections 7.4.1.1 and 7.4.1.2 of RFC 5246. During operational testing, the module was tested against an independent version of TLS and found to behave correctly.
- From this RFC 5288, the GCM cipher suites in use are TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, and TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- For IPsec/IKEv2, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with RFCs 4106 and 7296 (RFC 5282 is not applicable, as the module does not use GCM within IKEv2 itself), and ensures when the module exhausts all possible values for a given session key that this triggers a rekey condition. During operational testing, the module was tested against an independent version of IPsec with IKEv2 and found to behave correctly.
- For SSH, the module meets Scenario 1 of IG C.H. The module conforms to RFCs 4252, 4253, and 5647. The fixed field is 32 bits in length and is derived using the SSH KDF; this ensures the fixed field is unique for any given GCM session. The invocation field is 64 bits in length and is incremented for each invocation of GCM; this prevents the IV from repeating until the entire invocation field space of 264 is exhausted, which can take hundreds of years. (In FIPS-CC Mode, SSH rekey is automatically configured at 1 GB of data or 1 hour, whichever comes first.) In all the above cases, the nonce_explicit is always generated deterministically. AES GCM keys are zeroized when the module is power-cycled. For each new TLS or SSH session, a new AES GCM key is established. The module is compliant to IG C.F: The module utilizes Approved modulus sizes 2048, 3072, and 4096 bits for RSA signatures. This functionality has been CAVP tested as noted above. The minimum number of Miller Rabin tests for each modulus size is implemented according to Table C.2 of FIPS 186-4. For modulus size 4096, the module implements the largest number of Miller-Rabin tests shown in Table C.2. RSA SigVer is CAVP tested for all three supported modulus sizes as noted above. The module does not perform FIPS 186-2 SigVer. All supported modulus sizes are CAVP testable and tested as noted above. The module does not implement RSA key transport in the approved mode. The module does not have any algorithms that fall under: - Non-Approved Algorithms Allowed in the Approved Mode of Operation - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation Table 5 - Supported Protocols in the Approved Mode Supported Protocols* TLS 1.2 SSHv2 SNMPv3 IPsec and IKEv2 *Note: These protocols have not been tested or reviewed by the CMVP or the CAVP. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 8
| PhysicalPort | LogicalInterface | Datathatpassesoverport/interface |
|---|
| Power | PowerIn | Powersupplies |
| Console,GPCI/O | StatusOutput | Self-teststatusoutput |
| Ethernet | Datainput,controlinput, dataoutput,statusoutput | HTTPS,TLS,SNMP,IPsec,andSSHtrafficdata. |
Cryptographic Boundary The PAN-OS 11.0 VM-Series is a software cryptographic module and requires an underlying general purpose computer (GPC) environment. The module consists of a GPC (multi-chip standalone embodiment) with the cryptographic boundary defined below. The cryptographic boundary (CB) includes all of the software components of the module, which is included in the file name in Section 11 (PanOS_vm-11.0.3-h12) and also the configuration file that resides on the virtual machine’s virtual disk. The physical perimeter (PP) is defined by the enclosure around the host GPC on which it runs. Figure 1 depicts the boundary and illustrates the hardware components of a GPC. Figure 1 - Cryptographic Boundary 3. Cryptographic Module Interfaces The module is a software only module that operates on a general purpose computing (GPC) platform. The physical ports and logical interfaces are consistent with a GPC operating environment. The module supports the following FIPS 140-3 logical interfaces: Table 6 - Ports and Interfaces Physical Port Logical Interface Data that passes over port/interface Power Power In Power supplies Console, GPC I/O Status Output Self-test status output Ethernet Data input, control input, HTTPS, TLS, SNMP, IPsec, and SSH traffic data. data output, status output The module does not support a Control Output interface. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 9
| Role | Service | Input | Output |
|---|
| CryptoOfficer | ShowVersion | Querymoduleforversion | Moduleprovidesversion |
| CryptoOfficer, User | SecurityConfiguration Management | Configuringandmanaging cryptographicparametersand setting/modifyingsecuritypolicy, includingcreatingUseraccounts andadditionalCOaccountsviaCLI orWebUI | Confirmationofservice viaConfigurationLogs |
| CryptoOfficer | OtherConfiguration | Networkingparameter configuration,loggingconfiguration, andothernon-securityrelevant configurationviaCLIorWebUI | Confirmationofservice viaConfigurationLogs |
| CryptoOfficer, User | ViewOther Configuration | Querymoduleforcurrent non-securityrelevantconfiguration viaWebUIorCLI | Confirmationofservice viaConfigurationLogs |
| CryptoOfficer, User,RAVPN, S-SVPN | ShowStatus | Querystatusandversionofthe moduleviaWebUIorCLI | Modulestatusinformation viaCLIorSystemLogs |
| RAVPN,S-SVPN | VPN | InitializeVPNconnection | Confirmationofservice viaSystemLogs |
| CryptoOfficer | SoftwareUpdate | Loadingnewimage | Messageoutputnoting versionupdated successfully |
| Unauthenticated | Zeroize | Initiatezeroizationcommand | Thedevicewilloverwrite allCSPsandprovidestatus ofcompletion |
| Unauthenticated | Self-Tests | Powercyclingthemodule | Self-teststatusoutputvia systemlogs |
| Unauthenticated | ShowStatus (Hypervisor) | Viewstatusofthemodulevia hypervisor. | Modulestatusviathe hypervisor |
Table, extracted as text (did not parse into structured rows)
The module’s physical and electrical characteristics, manual controls, and physical indicators are provided by the host GPC; the hypervisors provide virtualized ports and interfaces which map to the GPCs’ physical ports and interfaces (i.e., network interfaces and GPC inputs/outputs). 4. Roles, Services, and Authentication Roles and Services While in the Approved mode of operation, all CO and User services are accessed via SSH or TLS sessions. Approved and allowed algorithms, relevant CSPs and public keys related to these protocols are accessed to support the following services. CSP access by services is further described in the following tables. Table 7 - Roles, Service Commands, Input and Output Crypto Officer Show Version Query module for version Module provides version Crypto Officer, Security Configuration Configuring and managing Confirmation of service User Management cryptographic parameters and via Configuration Logs setting/modifying security policy, including creating User accounts and additional CO accounts via CLI or WebUI Crypto Officer Other Configuration Networking parameter Confirmation of service configuration, logging configuration, via Configuration Logs and other non-security relevant configuration via CLI or WebUI Crypto Officer, View Other Query module for current Confirmation of service User Configuration non-security relevant configuration via Configuration Logs via WebUI or CLI Crypto Officer, Show Status Query status and version of the Module status information User, RA VPN, module via WebUI or CLI via CLI or System Logs RA VPN, S-S VPN VPN Initialize VPN connection Confirmation of service via System Logs Crypto Officer Software Update Loading new image Message output noting version updated Unauthenticated Zeroize Initiate zeroization command The device will overwrite all CSPs and provide status of completion Unauthenticated Power cycling the module Self-test status output via system logs Unauthenticated Show Status View status of the module via Module status via the © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 10
| Role | AuthenticationMethod | AuthenticationStrength |
|---|
| CryptographicOfficer | MemorizedSecret(Unique Username/password)and/or Single-FactorCryptographicSoftware (certificatecommonname/public key-basedauthentication) | Password-based Theminimumlengthiseight(8)characters1 (95possiblecharacters).Theprobabilitythat arandomattemptwillsucceedorafalse acceptancewilloccuris1/(958)whichisless than1/1,000,000. Theprobabilityof successfullyauthenticatingtothemodule withinoneminuteis10/(958),whichisless than1/100,000. Thefirewall’sconfiguration supportsatmosttenfailedattemptsto authenticateinaone-minuteperiod. Certificate/Publickey-based Thesecuritymodulessupportpublic-key basedauthenticationusingRSA2048and certificate-basedauthenticationusingRSA 2048,RSA3072,RSA4096,ECDSAP-256, P-384,orP-521. Theminimumequivalentstrengthsupported is112bits. Theprobabilitythatarandom attemptwillsucceedis1/(2112)whichisless than1/1,000,000. Theprobabilityof |
| User | MemorizedSecret(Unique Username/password)and/or Single-FactorCryptographicSoftware (certificatecommonname/public key-basedauthentication | |
| RemoteAccessVPN(RAVPN) | MemorizedSecret(Unique Username/password)and/or Single-FactorCryptographicSoftware (certificatecommonname/public key-basedauthentication | |
The zeroization procedure is invoked when the operator initiates the service. The operator must be in control of the module during the entire procedure to ensure that it has successfully completed. During the zeroization procedure, no other services are available. Note: Additional information on the configuration options the module provides can be found at https://docs.paloaltonetworks.com/ Assumption of Roles The modules support four distinct operator roles, User and Cryptographic Officer (CO), Remote Access VPN, and Site-to-site VPN. The cryptographic modules enforce the separation of roles using unique authentication credentials associated with operator accounts. The modules do not provide a maintenance role or bypass capability. The modules all support the use of a password (i.e. Memorized Secret as per SP 800-140E). Upon first boot, the module requires that the Cryptographic Officer change the password from the default one to a custom one. The module automatically enforces a minimum password length of at least 8 characters. In “FIPS-CC” mode, the module automatically enforces a maximum of 10 failed attempts. Passwords stored in the module are hashed using SHA-256, and any passwords that are transported into/out of the module are protected via TLS 1.2. Table 8 – Roles and Authentication Role Authentication Method Authentication Strength Cryptographic Officer Memorized Secret (Unique Password-based Username/password) and/or The minimum length is eight (8) characters1 Single-Factor Cryptographic Software (95 possible characters). The probability that (certificate common name / public a random attempt will succeed or a false key-based authentication) acceptance will occur is 1/(958) which is less User Memorized Secret (Unique than 1/1,000,000. The probability of Username/password) and/or successfully authenticating to the module Single-Factor Cryptographic Software within one minute is 10/(958), which is less (certificate common name / public than 1/100,000. The firewall’s configuration key-based authentication supports at most ten failed attempts to Remote Access VPN (RA VPN) Memorized Secret (Unique authenticate in a one-minute period. (certificate common name / public The security modules support public-key key-based authentication based authentication using RSA 2048 and certificate-based authentication using RSA 2048, RSA 3072, RSA 4096, ECDSA P-256, The minimum equivalent strength supported is 112 bits. The probability that a random attempt will succeed is 1/(2112) which is less than 1/1,000,000. The probability of In FIPS-CC Mode, the module checks and enforces the minimum password length of eight (8) as specified in SP 800-63B. Passwords are securely stored hashed with salt value, with very restricted access control, and rate limiting mechanism for authentication attempts. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 11
| | successfullyauthenticatingtothemodule withinaoneminuteperiodis 60,000,000/(2112),whichislessthan 1/100,000. Thefirewallsupportsatmost 60,000,000newsessionspersecondto authenticateinaone-minuteperiod. |
|---|
| Site-to-SiteVPN(S-SVPN) | IKE/IPSecPre-sharedkeys- IdentificationwiththeIPAddressand authenticationwiththePre-Shared Keyorcertificatebased authentication | Thepre-sharedkeyauthenticationmethod hasaminimumsecuritystrength2of956. The probabilityofsuccessfullyauthenticatingto themoduleis1/(956),whichislessthan 1/1,000,000. Thenumberofauthentication attemptsislimitedbythenumberofnew connectionspersecondsupported(120,000) onthefastestplatformofthePaloAlto Networksfirewalls. Theprobabilityof successfullyauthenticatingtothemodule withinaoneminuteperiodis 7,200,000/(956),whichislessthan 1/100,000. Thesecuritymodulessupportpublic-key basedauthenticationusingRSA2048and certificate-basedauthenticationusingRSA 2048,RSA3072,RSA4096,ECDSAP-256, P-384,orP-521. Theminimumequivalentstrengthsupported is112bits. Theprobabilitythatarandom attemptwillsucceedis1/(2112)whichisless than1/1,000,000. Theprobabilityof successfullyauthenticatingtothemodule withinaoneminuteperiodis 60,000,000/(2112),whichislessthan 1/100,000. Thefirewallsupportsatmost 60,000,000newsessionspersecondto authenticateinaone-minuteperiod. |
successfully authenticating to the module within a one minute period is 60,000,000/(2112), which is less than 1/100,000. The firewall supports at most 60,000,000 new sessions per second to authenticate in a one-minute period. Site-to-Site VPN (S-S VPN) IKE/IPSec Pre-shared keys - The pre-shared key authentication method Identification with the IP Address and has a minimum security strength2 of 956. The authentication with the Pre-Shared probability of successfully authenticating to Key or certificate based the module is 1/(956), which is less than attempts is limited by the number of new connections per second supported (120,000) on the fastest platform of the Palo Alto Networks firewalls. The probability of successfully authenticating to the module within a one minute period is 7,200,000/(956), which is less than The security modules support public-key based authentication using RSA 2048 and certificate-based authentication using RSA 2048, RSA 3072, RSA 4096, ECDSA P-256, The minimum equivalent strength supported is 112 bits. The probability that a random attempt will succeed is 1/(2112) which is less than 1/1,000,000. The probability of successfully authenticating to the module within a one minute period is 60,000,000/(2112), which is less than 1/100,000. The firewall supports at most 60,000,000 new sessions per second to authenticate in a one-minute period. Definition of CSPs Modes of Access The following table defines the relationship between access to CSPs and the different module services. The modes of access shown in the table are defined as: Note: The security strength (956) is based on the use of ASCII characters that are utilized, which surpasses the 6 character random number password allowance that sets a baseline minimum acceptable strength of 106. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 12
| Service | Description | ApprovedSecurity Functions | | Keysand/orSSPs | Roles | Accessrightsto Keysand/orSSPs | Indicator |
|---|
| ShowVersion | Querythemoduleto displaytheversion | N/A | | N/A | CO | N/A | VersiondisplayedviaSystem Logs/CLI/UI |
| Security Configuration Management | Configuringand managing cryptographic parametersand setting/modifying securitypolicy, includingcreating Useraccountsand additionalCO accounts | CKG RSAKeyGen(FIPS186-4) RSASigGen(FIPS186-4) | | RSAPrivateKeys | CO | G/W/E | Configuration/SystemLogs |
| | CKG ECDSAKeyGen (FIPS186-4) ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | CO | G/W/E | Configuration/SystemLogs |
| | KAS | TLSv1.2KDF RFC7627 | TLSPre-MasterSecret | CO | G/E/Z | Configuration/SystemLogs |
| | | TLSv1.2KDF RFC7627 | TLSMasterSecret | CO | G/E/Z | Configuration/SystemLogs |
| | | CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | TLSDHE/ECDHEPrivate Components | CO | G/E/Z | Configuration/SystemLogs |
| | | | TLSDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | KTS | HMAC-SHA2- 256 HMAC-SHA2- 384 | TLSHMACKeys | CO | G/E/Z | Configuration/SystemLogs |
| | | AES-CBC | TLSEncryptionKeys | CO | G/E/Z | Configuration/SystemLogs |
| | KTS | AES-GCM | | | | |
| | KTS | HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 512 | SSHSession AuthenticationKeys | CO | G/E/Z | Configuration/SystemLogs |
| | | AES-CBC, AES-CTR | SSHSessionEncryption Keys | CO | G/E/Z | Configuration/SystemLogs |
| | KTS | AES-GCM | | | | |
| | KAS | KDFSSH KAS-ECC-SSC KAS-FFC-SSC SafePrimes Key Generation, SafePrimes Key Verification | SSHDHE/ECDHE PrivateComponents | CO | G/E/Z | Configuration/SystemLogs |
| | | | SSHDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | N/A | | CO,User,RAVPN Password | CO | G/E/W | Configuration/SystemLogs |
| | CounterDRBG,ESV | | EntropyInputString DRBGSeed DRBGV | CO | G/E | Configuration/SystemLogs |
Table, extracted as text (did not parse into structured rows)
G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Table 9 - Approved Services Service Description Approved Security Keys and/or SSPs Roles Access rights to Indicator Functions Keys and/or SSPs Show Version Query the module to N/A N/A CO N/A Version displayed via System display the version Logs / CLI / UI Security Configuring and CKG RSA Private Keys CO G/W/E Configuration/System Logs security policy, ECDSA SigGen including creating (FIPS 186-4) User accounts and KAS TLS v1.2 KDF TLS Pre-Master Secret CO G/E/Z Configuration/System Logs accounts TLS v1.2 KDF TLS Master Secret CO G/E/Z Configuration/System Logs CKG, TLS DHE/ECDHE Private G/E/Z KeyGen (FIPS TLS DHE/ECDHE Public G/E/R/W/Z Safe Primes Safe Primes AES-CBC, SSH Session Encryption CO G/E/Z Configuration/System Logs KAS KDF SSH SSH DHE/ECDHE CO G/E/Z Configuration/System Logs Private Components KAS-FFC-SSC SSH DHE/ECDHE Public G/E/R/W/Z Safe Primes Components Safe Primes N/A CO, User, RA VPN CO G/E/W Configuration/System Logs Counter DRBG, ESV Entropy Input String CO G/E Configuration/System Logs DRBG Seed DRBG V © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 13
| | | | DRBGKey | | | |
|---|
| | KDFSNMP | | SNMPv3Authentication Secret | CO | W/E | Configuration/SystemLogs |
| | KDFSNMP | | SNMPv3PrivacySecret | CO | W/E | Configuration/SystemLogs |
| | HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 | | AuthenticationKey | CO | G/E/Z | Configuration/SystemLogs |
| | AES-CFB128 | | SessionKey | CO | G/E/Z | Configuration/SystemLogs |
| | N/A | | ProtocolSecrets | CO | W/E | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) | | CACertificates | CO | G/R/E/W | Configuration/SystemLogs |
| | ECDSASigVer (FIPS186-4) | | ECDSAPublicKeys | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer (FIPS186-4) | | RSAPublicKeys | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) | | SSHHostPublicKey | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) | | SSHClientPublicKey | CO | W/E | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) | | Publickeyforsoftware loadtest | CO | W/E | Configuration/SystemLogs |
| Other Configuration | Networking parameter configuration,logging configuration,and othernon-security relevantconfiguration | RSASigGen (FIPS186-4) | | RSAPrivateKeys | CO | G/W/E | Configuration/SystemLogs |
| | ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | CO | G/W/E | Configuration/SystemLogs |
| | KAS | TLSv1.2KDF RFC7627 | TLSPre-MasterSecret | CO | G/E/Z | Configuration/SystemLogs |
| | | TLSv1.2KDF RFC7627 | TLSMasterSecret | CO | G/E/Z | Configuration/SystemLogs |
| | | CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | TLSDHE/ECDHEPrivate Components | CO | G/E/Z | Configuration/SystemLogs |
| | | | TLSDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | HMAC-SHA2-256 HMAC-SHA2-384 | | TLSHMACKeys | CO | G/E/Z | Configuration/SystemLogs |
| | AES-CBCorAES-GCM | | TLSEncryptionKeys | CO | G/E/Z G/Z | Configuration/SystemLogs |
| | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | | SSHSession AuthenticationKeys | CO | | Configuration/SystemLogs |
| | AES-CBC,AES-CTR,or AES-GCM | | SSHSessionEncryption Keys | CO | G/E/Z | Configuration/SystemLogs |
| | KAS | KDFSSH CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | SSHDHE/ECDHE PrivateComponents SSHDHE/ECDHEPublic Components | CO | G/E/Z G/E/R/W/Z | Configuration/SystemLogs |
Table, extracted as text (did not parse into structured rows)
DRBG Key KDF SNMP SNMPv3 Authentication CO W/E Configuration/System Logs KDF SNMP SNMPv3 Privacy Secret CO W/E Configuration/System Logs N/A Protocol Secrets CO W/E Configuration/System Logs RSA SigVer (FIPS 186-4) CA Certificates CO G/R/E/W Configuration/System Logs ECDSA SigVer ECDSA SigVer ECDSA Public Keys CO G/R/E/W Configuration/System Logs RSA SigVer RSA Public Keys CO G/R/E/W Configuration/System Logs RSA SigVer (FIPS 186-4) SSH Host Public Key CO G/R/E/W Configuration/System Logs ECDSA SigVer RSA SigVer (FIPS 186-4) SSH Client Public Key CO W/E Configuration/System Logs RSA SigVer (FIPS 186-4) Public key for software CO W/E Configuration/System Logs load test Other Networking RSA SigGen RSA Private Keys CO G/W/E Configuration/System Logs configuration, logging ECDSA SigGen ECDSA Private Keys CO G/W/E Configuration/System Logs KAS TLS v1.2 KDF TLS Pre-Master Secret CO G/E/Z Configuration/System Logs relevant configuration TLS v1.2 KDF TLS Master Secret CO G/E/Z Configuration/System Logs CKG, TLS DHE/ECDHE Private CO G/E/Z Configuration/System Logs KeyGen (FIPS TLS DHE/ECDHE Public G/E/R/W/Z Safe Primes Safe Primes HMAC-SHA-1 SSH Session CO G/Z Configuration/System Logs AES-CBC, AES-CTR, or SSH Session Encryption CO G/E/Z Configuration/System Logs KAS KDF SSH SSH DHE/ECDHE CO G/E/Z Configuration/System Logs Private Components KeyGen (FIPS SSH DHE/ECDHE Public Safe Primes Safe Primes © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 14
| | N/A | | CO,User,RAVPN Password | CO | G/E/W | Configuration/SystemLogs |
|---|
| | RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) | | CACertificates | CO | G/R/E/W | Configuration/SystemLogs |
| | ECDSASigVer (FIPS186-4) | | ECDSAPublicKeys | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer (FIPS186-4) | | RSAPublicKeys | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) | | SSHHostPublicKey | CO | G/R/E/W | Configuration/SystemLogs |
| | RSASigVer(FIPS186-4) | | SSHClientPublicKey | CO | W/E | Configuration/SystemLogs |
| | CounterDRBG,ESV | | DRBGSeed DRBGV DRBGKey EntropyInputString | CO | G/E | Configuration/SystemLogs |
| ViewOther Configuration | Read-onlyof non-securityrelevant configuration | N/A | | CO,User,RAVPN Password Note:includesallitems in“OtherConfiguration” | CO,User | W/E | Configuration/SystemLogs |
| ShowStatus | Providesstatus informationofthe module | RSASigGen(FIPS186-4) | | RSAPrivateKeys | CO,User | E | Configuration/SystemLogs |
| | ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | CO,User | E | Configuration/SystemLogs |
| | KAS | TLSv1.2KDF RFC7627 | TLSPre-MasterSecret | CO,User | G/E/Z | Configuration/SystemLogs |
| | | TLSv1.2KDF RFC7627 | TLSMasterSecret | CO,User | G/E/Z | Configuration/SystemLogs |
| | | CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | TLSDHE/ECDHEPrivate Components | CO,User | G/E/Z | Configuration/SystemLogs |
| | | | TLSDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | HMAC-SHA2-256 HMAC-SHA2-384 | | TLSHMACKeys | CO,User | G/E/Z | Configuration/SystemLogs |
| | AES-CBCorAES-GCM | | TLSEncryptionKeys | CO,User | G/E/Z | Configuration/SystemLogs |
| | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | | SSHSession AuthenticationKeys | CO,User | G/E/Z | Configuration/SystemLogs |
| | AES-CBC,AES-CTR,or AES-GCM | | SSHSessionEncryption Keys | CO,User | G/E/Z | Configuration/SystemLogs |
| | KAS | KDFSSH CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | SSHDHEPublic/Private Components | CO,User | G/E/Z | Configuration/SystemLogs |
| | | | SSHECDHE Public/Private Components | | G/E/R/W/Z | |
Table, extracted as text (did not parse into structured rows)
N/A CO, User, RA VPN CO G/E/W Configuration/System Logs RSA SigVer (FIPS 186-4) CA Certificates CO G/R/E/W Configuration/System Logs ECDSA SigVer RSA SigVer RSA Public Keys CO G/R/E/W Configuration/System Logs RSA SigVer (FIPS 186-4) SSH Host Public Key CO G/R/E/W Configuration/System Logs ECDSA SigVer RSA SigVer (FIPS 186-4) SSH Client Public Key CO W/E Configuration/System Logs Counter DRBG, ESV DRBG Seed CO G/E Configuration/System Logs DRBG V DRBG Key Entropy Input String View Other Read-only of N/A CO, User, RA VPN CO, User W/E Configuration/System Logs Note: includes all items Show Status Provides status RSA SigGen (FIPS 186-4) RSA Private Keys CO, User E Configuration/System Logs information of the KAS TLS v1.2 KDF TLS Pre-Master Secret CO, User G/E/Z Configuration/System Logs TLS v1.2 KDF TLS Master Secret CO, User G/E/Z Configuration/System Logs CKG, TLS DHE/ECDHE Private CO, User G/E/Z Configuration/System Logs KeyGen (FIPS TLS DHE/ECDHE Public G/E/R/W/Z Safe Primes Safe Primes HMAC-SHA-1 SSH Session CO, User G/E/Z Configuration/System Logs AES-CBC, AES-CTR, or SSH Session Encryption CO, User G/E/Z Configuration/System Logs KAS KDF SSH SSH DHE Public/Private CO, User G/E/Z Configuration/System Logs ECDSA SSH ECDHE G/E/R/W/Z Safe Primes Safe Primes © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 15
| | CounterDRBG,ESV | | DRBGSeed DRBGV DRBGKey EntropyInputString | CO | G/E | Configuration/SystemLogs |
|---|
| VPN | Providenetwork accessforremote usersorsite-to-site connection | KTS | HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 | S-SVPNIPSec/IKE AuthenticationKeys | S-SVPN | G/E/Z | Configuration/SystemLogs |
| | | AES-CBC | S-SVPNIPSec/IKE SessionKeys | S-SVPN | G/E/Z | Configuration/SystemLogs |
| | KTS | AES-GCM | | | | |
| | KAS | KDFIKEv2 CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | S-SVPNIPSec/IKE DHE/ECDHEPrivate Components S-SVPNIPSec/IKE DHE/ECDHEPublic Components | S-SVPN | G/E/Z G/E/R/W/Z | Configuration/SystemLogs |
| | N/A | | S-SVPNIPSec Pre-SharedKeys | S-SVPN | W/E | Configuration/SystemLogs |
| | ECDSASigVer (FIPS186-4) | | ECDSAPublicKeys | S-SVPN | W/E | Configuration/SystemLogs |
| | RSASigVer (FIPS186-4) | | RSAPublicKeys | S-SVPN | W/E | Configuration/SystemLogs |
| | CounterDRBG,ESV | | DRBGSeed DRBGV DRBGKey EntropyInputString | CO | G/E | Configuration/SystemLogs |
| VPN | Providenetwork accessforremote usersorsite-to-site connection | RSASigGen (FIPS186-4) | | RSAPrivateKeys | RAVPN | E | Configuration/SystemLogs |
| | ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | RAVPN | E | Configuration/SystemLogs |
| | KAS | TLSv1.2KDF RFC7627 | TLSPre-MasterSecret | RAVPN | G/E/Z | Configuration/SystemLogs |
| | | TLSv1.2KDF RFC7627 | TLSMasterSecret | | G/E/Z | |
| | | CKG, ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimes Key Generation, SafePrimes Key Verification | TLSDHE/ECDHEPublic Components | RAVPN | G/E/R/W/Z | Configuration/SystemLogs |
| | | | TLSDHE/ECDHEPrivate Components | RAVPN | G/E/Z | Configuration/SystemLogs |
| | KTS | HMAC-SHA2- 256 HMAC-SHA2- 384 | TLSHMACKeys | RAVPN | G/E/Z | Configuration/SystemLogs |
| | | AES-CBC | TLSEncryptionKeys | RAVPN | G/E/Z | Configuration/SystemLogs |
| | KTS | AES-GCM | | | | |
| | CKG, AES-CBCorAES-GCM | | RAVPNIPSecSession Keys | RAVPN | G/E/Z | Configuration/SystemLogs |
| | CKG, HMAC-SHA-1 | | RAVPNIPSec Authentication | RAVPN | G/E/Z | Configuration/SystemLogs |
Table, extracted as text (did not parse into structured rows)
Counter DRBG, ESV DRBG Seed CO G/E Configuration/System Logs DRBG V DRBG Key Entropy Input String VPN Provide network HMAC-SHA-1 S-S VPN IPSec/IKE S-S VPN G/E/Z Configuration/System Logs KAS KDF IKEv2 S-S VPN IPSec/IKE S-S VPN G/E/Z Configuration/System Logs DHE/ECDHE Private Safe Primes Safe Primes N/A S-S VPN IPSec S-S VPN W/E Configuration/System Logs ECDSA SigVer ECDSA Public Keys S-S VPN W/E Configuration/System Logs RSA SigVer RSA Public Keys S-S VPN W/E Configuration/System Logs Counter DRBG, ESV DRBG Seed CO G/E Configuration/System Logs DRBG V DRBG Key Entropy Input String VPN Provide network RSA SigGen RSA Private Keys RA VPN E Configuration/System Logs access for remote (FIPS 186-4) users or site-to-site ECDSA SigGen ECDSA Private Keys RA VPN E Configuration/System Logs KAS TLS v1.2 KDF TLS Pre-Master Secret RA VPN G/E/Z Configuration/System Logs TLS v1.2 KDF TLS Master Secret G/E/Z CKG, TLS DHE/ECDHE Public RA VPN G/E/R/W/Z Configuration/System Logs KeyGen (FIPS TLS DHE/ECDHE Private RA VPN G/E/Z Configuration/System Logs Safe Primes Safe Primes AES-CBC TLS Encryption Keys RA VPN G/E/Z Configuration/System Logs CKG, RA VPN IPSec Session RA VPN G/E/Z Configuration/System Logs CKG, RA VPN IPSec RA VPN G/E/Z Configuration/System Logs © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 16
| | CounterDRBG,ESV | EntropyInputString DRBGSeed DRBGV DRBGKey | RAVPN | G/E | Configuration/SystemLogs |
|---|
| | RSASigVer(FIPS186-4)) ECDSASigVer (FIPS186-4) | CACertificates | RAVPN | W/E | Configuration/SystemLogs |
| | ECDSASigVer (FIPS186-4) | ECDSAPublicKeys | RAVPN | W/E | Configuration/SystemLogs |
| | RSASigVer (FIPS186-4) | RSAPublicKeys | RAVPN | W/E | Configuration/SystemLogs |
| Software Update | Providesamethodto updatethesoftwareof themodule | RSASigVer (FIPS186-4) | Publickeyforsoftware contentloadtest Note:Includesallkeys fromOther Configuration | CO | E | Configuration/SystemLogs |
| Zeroize | Destroysallkeysin themodule | N/A | AllkeysandSSPs | CO | Z | Zeroizationindicator |
| Self-Test | Initiatesself-testsand integritytest | HMAC-SHA2-256, ECDSASigVer (FIPS186-4) | Softwareintegrity verificationkey | CO | E | SystemLogs |
| ShowStatus (Hypervisor) | Providesstatusofthe module | N/A | N/A | All | R | LEDs |
Table, extracted as text (did not parse into structured rows)
Counter DRBG, ESV Entropy Input String RA VPN G/E Configuration/System Logs DRBG Seed DRBG V DRBG Key RSA SigVer (FIPS 186-4)) CA Certificates RA VPN W/E Configuration/System Logs ECDSA SigVer (FIPS 186-4) ECDSA SigVer ECDSA Public Keys RA VPN W/E Configuration/System Logs (FIPS 186-4) RSA SigVer RSA Public Keys RA VPN W/E Configuration/System Logs (FIPS 186-4) Software Provides a method to RSA SigVer Public key for software CO E Configuration/System Logs Update update the software of (FIPS 186-4) content load test the module Note: Includes all keys from Other Zeroize Destroys all keys in N/A All keys and SSPs CO Z Zeroization indicator the module Self-Test Initiates self-tests and HMAC-SHA2-256, Software integrity CO E System Logs integrity test ECDSA SigVer verification key (FIPS 186-4) Show Status Provides status of the N/A N/A All R LEDs Note: Configuration/System Logs for Approved services above will indicate FIPS-CC mode is enabled, configuration requirements from Section 11 are followed, and that the service succeeded. 5. Software/Firmware Security The module performs the Software Integrity test by using HMAC-SHA-256 (HMAC Cert. #A3454) during the Pre-Operational Self-Test. In addition, the module also conducts a software load test by using the Public Verification Key (RSA 2048 with SHA-256, Cert. #A3454) for the new validated software to be uploaded into the module. Any software loaded into this module that is not shown on the module certificate is out of scope of this validation, and requires a separate FIPS 140-3 validation. 6. Operational Environment The module is a modifiable operational environment as per FIPS 140-3 Level 1 specifications. The hypervisor environment provides an isolated operating environment and is the single operator of the virtual machine. The tested operating environments isolate virtual systems into separate isolated process spaces. Each process space is logically separated from all other processes by the operating environments software and hardware. The module functions entirely within the process space of the isolated system as managed by the single operational environment. This implicitly meets the FIPS 140-3 requirement that only one (1) entity at a time can use the cryptographic module. 7. Physical Security There are no applicable FIPS 140-3 physical security requirements. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 17
| Key/SSP/Name/Ty pe | Strength | SecurityFunction andCert.Number | Generation | Import/Expo rt | Establishment | Storage | Zeroization1 | Use&RelatedKeys |
|---|
| CACertificates | 112bits minimum | RSASigVer(FIPS 186-4) ECDSASigVer (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD–Zeroize Service RAM-Zeroizeat session termination | ECDSA/RSAPublic key-Usedtotrusta rootCAintermediate CAandleaf/endentity certificates (RSA2048,3072,and 4096bits) (ECDSAP-256,P-384, andP-521) |
| RSAPublicKeys | 112bits minimum | RSASigVer (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encryptedor Plaintext TLS handshake | N/A | HDD/RAM– plaintext | ZeroizeService | RSApublickeys managedas certificatesforthe verificationof signatures, establishmentofTLS, operator authenticationand peerauthentication. (RSA2048,3072,or 4096-bit) |
| RSAPrivateKeys | 112bits minimum | RSASigGen (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD–Zeroize Service RAM-Zeroizeat session termination | RSAPrivatekeysfor generationof signatures, authenticationorkey establishment. (RSA2048,3072,or 4096-bit) |
| ECDSAPublic Keys | 128bits minimum | ECDSASigVer (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encryptedor Plaintext TLS handshake | N/A | HDD/RAM– plaintext | ZeroizeService | ECDSApublickeys managedas certificatesforthe verificationof signatures, establishmentofTLS, operator authenticationand peerauthentication. (ECDSAP-256,P-384, orP-521) |
| ECDSAPrivate Keys | 128bits minimum | ECDSASigGen (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD–Zeroize Service RAM-Zeroizeat session termination | ECDSAPrivatekeyfor generationof signaturesand authentication (P-256,P-384,or P-521) |
| TLSDHE/ECDHE Private Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DRBG,SP 800-56A Rev.3 | N/A | N/A | RAM- plaintext | Zeroizeat session termination | Ephemeral Diffie-Hellmanprivate FFCorECcomponent usedinTLS (DHE2048,ECDHE P-256,P-384,P-521) |
| TLSDHE/ECDHE Public Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DRBG,SP 800-56A Rev.3 | Plaintext- TLS handshake | N/A | N/A | Zeroizeat session termination | Diffie_HellmanorEC Diffie-Hellman Ephemeralvaluesused inkeyagreement |
- Non-Invasive Security No Approved non-invasive attack mitigation test metrics are defined at this time.
- Sensitive Security Parameters The following table details all the sensitive security parameters utilized by the module. Table 10 - SSPs key - Used to trust a RSA SigVer (FIPS HDD – Zeroize root CA intermediate TLS or SSH Service CA and leaf /end entity managed as certificates for the verification of RSA SigVer signatures, peer authentication. (RSA 2048, 3072, or RSA Private keys for RSA SigGen TLS or SSH Service signatures, managed as certificates for the verification of peer authentication. generation of
112 bits RAM - FFC or EC component
112 bits Diffie-Hellman
minimum Ephemeral values used in key agreement © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 18
| | | | | | | | (DHE2048,ECDHE P-256,P-384,P-521) |
|---|
| TLSPre-Master Secret | N/A | TLSv1.2KDF RFC7627 Cert.#A3454 | KASSP 800-56A Rev.3 | N/A | N/A | RAM– plaintext | Zeroizeat session termination | Secretvalueusedto derivetheTLSMaster Secretalongwith clientandserver randomnonces |
| TLSMasterSecret | N/A | TLSv1.2KDF RFC7627 Cert.#A3454 | TLSv1.2 KDF RFC7627 | N/A | N/A | RAM– plaintext | Zeroizeat session termination | Secretvalueusedto derivetheTLSsession keys |
| TLSEncryption Keys | 128bits minimum | AES-CBCor AES-GCM Cert.#A3454 | TLSv1.2 KDF RFC7627 | N/A | TLS,KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | AES(128or256bit) keysusedinTLS connections(GCM; CBC) |
| TLSHMACKeys | 256bits minimum | HMAC-SHA2-256 HMAC-SHA2-384 Cert.#A3454 | TLSv1.2 KDF RFC7627 | N/A | TLS,KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | HMACkeysusedin TLSconnections (SHA2-256/384) (256,384bits) |
| SSHDHE/ECDHE Private Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DRBG,SP 800-56A Rev.3 | N/A | N/A | RAM- plaintext | Zeroizeat session termination | DiffieHellmanorEC Diffie-Hellmanprivate (DHGroup14,ECDH P-256,ECDHP-384, ECDHP-521) |
| SSHDHE/ECDHE Public Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DRBG,SP 800-56A Rev.3 | Plaintext SSH handshake | N/A | RAM- plaintext | Zeroizeat session termination | DiffieHellmanorEC Diffie-Hellmanpublic component(DHGroup 14,ECDHP-256, ECDHP-384,ECDH P-521) |
| SSHHostPublic Key | 112bits minimum | RSASigVer (FIPS186-4) ECDSASigVer (FIPS186-4) Cert.#A3454 | DRBG,FIPS 186-4 | N/A | N/A | HDD/RAM– plaintext | ZeroizeService | SSHHostPublicKey (RSA2048,RSA3072, RSA4096,ECDSA P-256,P-384,or P-521) |
| SSHClientPublic Key | 112bits minimum | RSASigVer (FIPS186-4) Cert.#A3454 | N/A | Encrypted viaSSHor TLS | N/A | HDD/RAM– plaintext | ZeroizeService | PublicRSAkeyusedto authenticateclient. (RSA2048,3072,and 4096bits) |
| SSHSession EncryptionKeys | 128bits minimum | AES-CBC, AES-CTR,or AES-GCM Cert.#A3454 | KDFSSH | N/A | SSH,KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | UsedinallSSH connectionstothe securitymodule’s commandline interface. (128,192,or256bits: AESCBCorCTR) (128or256bits:AES GCM) |
| SSHSession Authentication Keys | 160bits minimum | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 Cert.#A3454 | KDFSSH | N/A | SSH,KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | Authenticationkeys usedinallSSH connectionstothe securitymodule’s commandline interface (HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-512) (160,256,512bits) |
| S-SVPNIPSec/IKE DHEorECDHE Private Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DBRG,SP 800-56A Rev.3 | N/A | N/A | RAM- plaintext | Powercycle | Diffie-HellmanorEC Diffie-Hellmanprivate componentusedinkey establishment (DHE2048,DHE 3072,DHE4096, ECDHEP-256,P-384, P-521) |
| S-SVPNIPSec/IKE DHEorECDHE Public Components | 112bits minimum | KAS-ECC-SSC KAS-FFC-SSC Cert.#A3454 | DRBG,SP 800-56A Rev.3 | N/A | N/A | RAM- plaintext | Powercycle | Diffie-HellmanorEC Diffie-Hellmanpublic componentusedinkey agreement (DHE2048,DHE 3072,DHE4096, ECDHEP-256,P-384, P-521) |
Table, extracted as text (did not parse into structured rows)
Secret value used to TLS v1.2 KDF KAS SP Zeroize at derive the TLS Master random nonces TLS v1.2 KDF TLS v1.2 Zeroize at Secret value used to TLS Encryption 128 bits RAM - keys used in TLS HMAC keys used in Diffie Hellman or EC
112 bits RAM -
Diffie Hellman or EC
Table, extracted as text (did not parse into structured rows)
112 bits SSH RAM - component (DH Group
RSA SigVer (RSA 2048, RSA 3072, N/A N/A Zeroize Service RSA 4096, ECDSA Public RSA key used to RSA SigVer Encrypted SSH Client Public 112 bits HDD/RAM – authenticate client. (FIPS 186-4) N/A via SSH or N/A Zeroize Service
4096 bits)
Table, extracted as text (did not parse into structured rows)
Used in all SSH connections to the security module’s SSH, KAS SP Zeroize at command line used in all SSH connections to the HMAC-SHA-1 security module’s Diffie-Hellman or EC S-S VPN IPSec/IKE component used in key Diffie-Hellman or EC S-S VPN IPSec/IKE component used in key © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 19
| S-SVPNIPSec/IKE SessionKeys | 128bits minimum | AES-CBC, AES-GCM Cert.#A3454 | KDFIKEv2 | N/A | IPSec/IKE, KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | Usedtoencrypt IKE/IPSecdata.These areAES(128,192,or 256CBC)IKEkeys and(128,192or256 CBC,128or256 GCM)IPSeckeys |
|---|
| S-SVPNIPSec/IKE Authentication Keys | 160bits minimum | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 Cert.#A3454 | KDFIKEv2 | N/A | IPSec/IKE, KASSP 800-56ARev. 3 | RAM- plaintext | Zeroizeat session termination | (HMAC-SHA-1, SHA-256,SHA-384or SHA-512)Usedto authenticatethepeer inanIKE/IPSectunnel connection.(160,256, 384,512bits) |
| S-SVPNIPSec Pre-SharedKeys | N/A | N/A | N/A | Encrypted viaSSHor TLS | N/A | HDD/RAM– plaintext | ZeroizeService | PSKusedin conjunctionwith HMAClistedabovefor authentication. Enteredintothe modulebytheCrypto Officeronce authenticated |
| RAVPNIPSec SessionKeys | 128bits minimum | AES-CBCor AES-GCM Cert.#A3454 | CKG, DRBG | N/A | N/A | RAM- plaintext | Zeroizeat session termination | Usedtoencrypt remoteaccess sessionsutilizing IPSec.(AES128-CBC, 128/256-GCM) |
| RAVPNIPSec Authentication | 160bits | HMAC-SHA-1 Cert.#A3454 | CKG, DRBG | N/A | N/A | RAM- plaintext | Zeroizeat session termination | (HMAC-SHA-1,160 bits) Usedinauthentication ofremoteaccessIPSec data. |
| Softwareintegrity verificationkey | 128bits | HMAC-SHA2-256, ECDSASigVer (FIPS186-4) Cert.#A3454 | N/A | N/A | N/A | HDD- plaintext | N/A | Usedtocheckthe integrityofall softwarecode (HMAC-SHA-256and ECDSAP-256) (Note:Thisisnot consideredanSSP) |
| Publickeyfor softwarecontent loadtest | 112bits | RSASigVer (FIPS186-4) Cert.#A3454 | N/A | N/A | N/A | HDD- plaintext | N/A | Usedtoauthenticate software/firmware andcontenttobe installedonthe firewall(RSA2048 withSHA-256) |
| CO,User,RAVPN Password | N/A | SHA2-256 Cert.#A3454 | External | Encrypted viaSSHor TLS | N/A | HDD-a passwordhash (SHA2-256) | ZeroizeService | Authenticationstring withaminimumlength ofeight(8)characters. |
| ProtocolSecrets | N/A | N/A | N/A | Encrypted viaIPsec, SSHorTLS | N/A | HDD/RAM– plaintext | ZeroizeService | Secretsusedby RADIUSorTACACS+ (8characters minimum) |
| EntropyInput String | 256bits | CKG(vendor affirmed),Counter DRBG Cert.#A3454 | Entropyas per SP800-90B | N/A | N/A | RAM- plaintext | Powercycle | Entropyinputstring comingfromthe entropysource Inputlength=384 bits |
| DRBGSeed | 256bits | CKG(vendor affirmed),Counter DRBG Cert.#A3454 | Entropyas per SP800-90B | N/A | N/A | RAM- Plaintext | Powercycle | DRBGseedcoming fromtheentropy source Seedlength=384bits |
| DRBGKey | 256bits | CKG(vendor affirmed),Counter DRBG Cert.#A3454 | Entropyas per SP800-90B | N/A | N/A | RAM- plaintext | Powercycle | AES256CTRDRBG stateKeyusedinthe generationofa randomvalues |
| DRBGV | 128bits | CKG(vendor affirmed),Counter DRBG | Entropyas per SP800-90B | N/A | N/A | RAM- plaintext | Powercycle | AES256CTRDRBG stateVusedinthe |
Table, extracted as text (did not parse into structured rows)
Used to encrypt S-S VPN IPSec/IKE HMAC-SHA2-256 Zeroize at SHA-512) Used to Authentication HMAC-SHA2-384 KDF IKEv2 N/A session authenticate the peer PSK used in conjunction with HMAC listed above for N/A N/A N/A via SSH or N/A Zeroize Service Pre-Shared Keys plaintext Entered into the module by the Crypto Officer once Used to encrypt AES-CBC or Zeroize at remote access Zeroize at bits) termination of remote access IPSec Used to check the integrity of all software code Software integrity ECDSA SigVer HDD verification key (FIPS 186-4) plaintext ECDSA P-256) (Note: This is not considered an SSP) Used to authenticate Public key for RSA SigVer HDD - and content to be software content 112 bits (FIPS 186-4) N/A N/A N/A N/A plaintext installed on the load test Cert. #A3454 firewall (RSA 2048 N/A External via SSH or N/A password hash Zeroize Service with a minimum length Secrets used by Protocol Secrets N/A N/A N/A via IPsec, N/A Zeroize Service affirmed), Counter coming from the Entropy as DRBG seed coming Entropy as from the entropy Seed length = 384 bits Entropy as DRBG RAM - state Key used in the DRBG Key 256 bits per N/A N/A Power cycle plaintext generation of a Cert. #A3454 random values Entropy as DRBG plaintext state V used in the © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 20
| | Cert.#A3454 | | | | | | generationofa randomvalues |
|---|
| SNMPv3 Authentication Secret | N/A | KDFSNMP Cert.#A3454 | N/A | Encrypted viaTLS/SSH | N/A | HDD/RAM– plaintext | ZeroizeService | Usedtosupport SNMPv3services (Minimum8 characters) |
| SNMPv3Privacy Secret | N/A | KDFSNMP Cert.#A3454 | N/A | Encrypted viaTLS/SSH | N/A | HDD/RAM– plaintext | ZeroizeService | Usedtosupport SNMPv3services (Minimum8 characters) |
| Authentication Key | 160bits minimum | HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 Cert.#A3454 | KDFSNMP | N/A | N/A | HDD/RAM- Plaintext | ZeroizeService | HMAC–SHA-1/224/2 56/384/512 Authentication protocolkey(160bits) |
| SessionKey | 128bits minimum | AES-CFB Cert.#A3454 | KDFSNMP | N/A | N/A | HDD/RAM- Plaintext | ZeroizeService | Privacyprotocol encryptionkey (AES128/192/256 CFB) |
| EntropySource | Minimumnumberofbitsof entropy | Details |
|---|
| PaloAltoNetworksDRNGEntropy Source | 256bits | ESVCert.#E69 Entropysourceprovidesfullentropy,whichis providedinthe384bitseed. |
Cert. #A3454 generation of a random values SNMPv3 Used to support N/A N/A N/A Zeroize Service Used to support SNMPv3 Privacy KDF SNMP Encrypted HDD/RAM
- SNMPv3 services N/A N/A N/A Zeroize Service KDF SNMP N/A N/A Zeroize Service HMAC-SHA2-512 protocol key (160 bits) Privacy protocol Session Key KDF SNMP N/A N/A Zeroize Service Note: SSPs are implicitly zeroized when power is lost, or explicitly zeroized by the zeroize service. In the case of implicit zeroization, the SSPs are implicitly overwritten with random values due to their ephemeral memory being reset upon power loss. For the zeroization service and zeroization at session termination, the SSP's memory location is overwritten with random values. Table 11 - Non-Deterministic Random Number Generation Specification Entropy Source Minimum number of bits of Details Palo Alto Networks DRNG Entropy 256 bits Source Entropy source provides full entropy, which is provided in the 384 bit seed. 10. Self-Tests The cryptographic module performs the following tests below. The operator can command the module to perform the pre-operational and cryptographic algorithm self-tests by cycling power of the module; these tests do not require any additional operator action. Pre-operational Self-Tests Pre-operational Software Integrity Test
- Verified with HMAC-SHA-256 and ECDSA P-256 Note: the ECDSA and HMAC-SHA-256 KATs are performed prior to the Software integrity test Conditional self-tests Cryptographic algorithm self-tests
- AES 128-bit ECB Encrypt Known Answer Test*
- AES 128-bit ECB Decrypt Known Answer Test* *Note: Supported by the module cryptographic implementation, but only utilized for CAST
- AES 128-bit CMAC Known Answer Test* *Note: Supported by the module cryptographic implementation, but only utilized for CAST
- AES 256-bit GCM Encrypt Known Answer Test
- AES 256-bit GCM Decrypt Known Answer Test © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 21
| CauseofError | ErrorStateIndicator |
|---|
| ConditionalCryptographicAlgorithmSelf-Testor SoftwareIntegrityTestFailure | FIPS-CCmodefailure. <Algorithmtest>failed. |
| ConditionalPairwiseConsistencyorCriticalFunctions TestFailure | Systemlogprintsanerrormessage. |
| ConditionalSoftwareLoadTestFailure | SystemprintsInvalidimagemessage. |
- AES 192-bit CCM Encrypt Known Answer Test*
- AES 192-bit CCM Decrypt Known Answer Test* *Note: Supported by the module cryptographic implementation, but only utilized for CAST
- RSA 2048-bit PKCS#1 v1.5 with SHA-256 Sign Known Answer Test
- RSA 2048-bit PKCS#1 v1.5 with SHA-256 Verify Known Answer Test
- RSA 2048-bit Encrypt Known Answer Test
- RSA 2048-bit Decrypt Known Answer Test Note: RSA Encrypt/Decrypt are only used for self-tests
- ECDSA P-256 with SHA-512 Sign Known Answer Test
- ECDSA P-256 with SHA-512 Verify Known Answer Test
- HMAC-SHA-1 Known Answer Test
- HMAC-SHA-256 Known Answer Test
- HMAC-SHA-384 Known Answer Test
- HMAC-SHA-512 Known Answer Test
- SHA-1 Known Answer Test
- SHA-256 Known Answer Test
- SHA-384 Known Answer Test
- SHA-512 Known Answer Test
- DRBG SP 800-90Arev1 Instantiate/Generate/Reseed Known Answer Tests
- SP 800-90Arev1 Instantiate/Generate/Reseed Section 11.3 Health Tests
- SP 800-56Ar3 KAS-FFC-SSC 2048-bit Known Answer Test
- SP 800-56Ar3 KAS-ECC-SSC P-256 Known Answer Test
- SP 800-135rev1 TLS 1.2 with SHA-256 KDF Known Answer Test
- SP 800-135rev1 SSH KDF with SHA-256 Known Answer Test
- SP 800-135rev1 IKEv2 KDF with SHA-256 Known Answer Test
- SP 800-90B RCT/APT Health Tests on Entropy Source Note: The SP 800-90B Health Tests are implemented by the entropy source. Conditional Pairwise Consistency Self-Tests
- RSA Pairwise Consistency Test
- ECDSA/KAS-ECC Pairwise Consistency Test
- KAS-FFC Pairwise Consistency Test Conditional Software Load test
- Software Load Test
- Verify RSA 2048 with SHA-256 signature on software at time of load Conditional Critical Functions Tests
- SP 800-56A Rev. 3 Assurance Tests (Based on Sections 5.5.2, 5.6.2, and 5.6.3) Error Handling In the event of a conditional test failure, the module will output a description of the error. These are summarized below. Table 12 - Errors and Indicators Cause of Error Error State Indicator Conditional Cryptographic Algorithm Self-Test or FIPS-CC mode failure. <Algorithm test> failed. Software Integrity Test Failure Conditional Pairwise Consistency or Critical Functions System log prints an error message. Test Failure Conditional Software Load Test Failure System prints Invalid image message. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 22
- Life-Cycle Assurance The vendor provided life-cycle assurance documentation describes configuration management, design, finite state model, development, testing, delivery & operation, end of life procedures, and guidance. For details regarding the approved mode of operation, see “Approved Mode of Operation''. For details regarding secure installation, initialization, startup, and operation of the module, see below. Installation Instructions The module can be retrieved by downloading PanOS_vm-11.0.3-h12 from the support site: https://support.paloaltonetworks.com/Support/Index, and a checksum (SHA-256) is available to ensure the module is correct: PanOS_vm-11.0.3-h12: 6c3522db244bdd200075038d4eb5fff580c1d49610fab75e7e9f28f65b451017 Alternatively, the VM-Series version can be obtained by running the following commands via CLI (as an authorized administrator): 1. request system software check 2. request system software download version 11.0.3-h12 3. request system software install version 11.0.3-h12 4. request restart system Palo Alto Network provides an Administrator Guide for additional information noted in the “Reference Documents” section of this Security Policy. The module design corresponds to the module security rules noted in the section below. Module Enforced Security Rules This section documents the security rules enforced by the cryptographic module to implement the security requirements of this FIPS 140-3 Level 1 module.
- The cryptographic module provides four distinct operator roles. These are the User role, Remote Access VPN role, Site-to-site VPN role, and the Cryptographic Officer role.
- The cryptographic module provides identity-based authentication.
- The cryptographic module clears previous authentications when a power cycle is performed.
- If the cryptographic module remains inactive in any valid role for the administrator specified time interval, the module will automatically log out the operator. The CO will configure the period of inactivity.
- When the module has not been placed in a valid role, the operator does not have access to any cryptographic services.
- The operator can command the module to perform the power-up self-test by cycling power of the module.
- Power-up self-tests do not require any operator action.
- Data output is inhibited during power-up self-tests, zeroization, and error states.
- Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
- There are no restrictions on which keys or CSPs are zeroized by the zeroization service.
- The module does not support a maintenance interface or role.
- The module does not have any external input/output devices used for entry/output of data.
- The module does not enter or output plaintext CSPs. © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 23
- The module does not output intermediate key generation values.
- Pre-shared keys used for IKE/IPsec must be at least 6 bytes in length, but no more than 255 bytes. Vendor Imposed Security Rules In FIPS-CC mode, the following rules shall apply:
- The operator should not enable TLSv1.0 or use RSA for key wrapping; it is disabled by default. a. Checked via CLI using “show shared” command
- The operator should not enable TLSv1.3, it is disabled by default. a. Checked via CLI using “show profiles” command
- If using RADIUS, it must be configured using TLS. a. Checked via CLI using “show shared” command
- If using TACACS+, configure the service route via an IPSec tunnel, and ensure the TACACS+ server is configured for a minimum password length of eight (8) characters or greater. a. Checked via CLI using “show deviceconfig” command Failure to follow these Security Rules will cause the module to operate in a non-compliant state. Key to Entity The cryptographic module associates all keys (secret, private, or public) stored within, entered into or output from the module with authenticated operators of the module. Keys stored within the module are only made available to authenticated operators via TLS or SSH. Keys are only input or output from the module by the authenticated operator via a SSH/TLS/IPsec protected communication. Any attempt to intervene in the key to entity relationship would require defeating the module TLS/SSH/IPsec encryption and authentication/integrity mechanism.
- Mitigation of Other Attacks The module is not designed to mitigate any specific attacks outside the scope of FIPS 140-3. These requirements are not applicable.
- References [FIPS 140-3] FIPS Publication 140-3 Security Requirements for Cryptographic Modules Palo Alto Networks Administrator’s Guide: https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/pan-os/11-0/pan-os-admin/pan-os-admin.pdf
- Definitions and Acronyms AES – Advanced Encryption Standard CA – Certificate Authority CLI – Command Line Interface © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 24
CO
- Crypto-Officer CSP
- Critical Security Parameter CVL
- Component Validation List DB9
- D-sub series, E size, 9 pins DES
- Data Encryption Standard DH
- Diffie-Hellman DRBG
- Deterministic Random Bit Generator EDC
- Error Detection Code ECDH
- Elliptical Curve Diffie-Hellman ECDSA
- Elliptical Curve Digital Signature Algorithm FIPS
- Federal Information Processing Standard HMAC
- (Keyed) Hashed Message Authentication Code KDF
- Key Derivation Function LED
- Light Emitting Diode RJ45
- Networking Connector RNG –Random number generator RSA
- Algorithm developed by Rivest, Shamir and Adleman SHA
- Secure Hash Algorithm SNMP
- Simple Network Management Protocol SSH
- Secure Shell TLS
- Transport Layer Security USB
- Universal Serial Bus VGA
- Video Graphics Array © 2024 Palo Alto Networks, Inc. PAN-OS 11.0 VM-Series Security Policy 25