All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Panorama 10.2 M-200, M-300, M-600 and M-700

Certificate#4777StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusHistoricalVendorPalo Alto Networks, Inc.
Medium review priority  ·  exposes firmware-update authentication  ·  last validated 23 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusHistorical
CaveatInterim Validation. When operated in approved mode and when installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy
VendorPalo Alto Networks, Inc.

Approved Algorithms (31)

AlgorithmACVP Cert
AES-CBCA2906
AES-CFB128A2906
AES-CTRA2906
AES-GCMA2906
Conditioning Component AES-CBC-MAC SP800-90BA2165
Conditioning Component AES-CBC-MAC SP800-90BA2518
Counter DRBGA2906
ECDSA KeyGen (FIPS186-4)A2906
ECDSA KeyVer (FIPS186-4)A2906
ECDSA SigGen (FIPS186-4)A2906
ECDSA SigVer (FIPS186-4)A2906
HMAC-SHA-1A2906
HMAC-SHA2-224A2906
HMAC-SHA2-256A2906
HMAC-SHA2-384A2906
HMAC-SHA2-512A2906
KAS-ECC-SSC Sp800-56Ar3A2906
KAS-FFC-SSC Sp800-56Ar3A2906
KDF SNMPA2906
KDF SSHA2906
KDF TLSA2906
RSA KeyGen (FIPS186-4)A2906
RSA SigGen (FIPS186-4)A2906
RSA SigVer (FIPS186-4)A2906
Safe Primes Key GenerationA2906
Safe Primes Key VerificationA2906
SHA-1A2906
SHA2-224A2906
SHA2-256A2906
SHA2-384A2906
SHA2-512A2906

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Panorama 10.2 M-200, M-300, M-600 and M-700
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>self-test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Panorama 10.2 M-200, M-300, M-600 and M-700
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>self-test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Panorama 10.2 M-200, M-300, M-600 and M-700 Version: 1.1 Revision Date: August 1, 2024 Palo Alto Networks, Inc. www.paloaltonetworks.com © 2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.

Page 2
Table of Contents
#SectionPage
Page 3

1. General The Panorama 10.2 M-200, M-300, M-600 and M-700 from Palo Alto Networks Inc., hereafter referred to as “Panorama M-Series”, “Panorama HW”, “modules”, or the “cryptographic modules” are multi-chip standalone cryptographic modules designed to fulfill FIPS 140-3 level 2 requirements. Panorama M-Series management appliances provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall. The Panorama M-Series management appliances’ individual management and logging components can be separated in a distributed manner to accommodate large volumes of log data. Panorama M-Series management appliances can be deployed in the following ways:

Page 4
ISO/IEC24759 Section6.FIPS140-3SectionTitleSecurity Level
1General2
2CryptographicModuleSpecification2
3CryptographicModuleInterfaces2
4Roles,Services,Authentication3
5Software/FirmwareSecurity2
6OperationalEnvironmentN/A
7PhysicalSecurity2
8Non-InvasiveSecurityN/A
9SensitiveSecurityParameterManagement2
10Self-Tests2
11Life-CycleAssurance3
12MitigationofOtherAttacksN/A
OverallLevel2
Table, extracted as text (did not parse into structured rows)
The cryptographic module meets the overall requirements applicable to Level 2 security of FIPS 140-3. Table 1 - Security Levels ISO/IEC 24759               FIPS 140-3 Section Title                Security Section 6.                                                         Level
2        Cryptographic Module Specification                     2
3        Cryptographic Module Interfaces                        2
6        Operational Environment                               N/A
7        Physical Security                                      2
9        Sensitive Security Parameter Management                2
11        Life-Cycle Assurance                                   3
12        Mitigation of Other Attacks                           N/A
Overall Level                                 2 © 2024 Palo Alto Networks, Inc.                                                        Panorama HW 10.2 Security Policy 4
Page 5
ModuleHardwareFirmwareVersionDistinguishingFeatures
PanoramaM-200910-000176 PhysicalKit:920-00020810.2.3-h1RJ45interfaces,USBports,LEDs
PanoramaM-300910-000271 PhysicalKit:920-00031910.2.3-h1RJ45interfaces,USBports,LEDs
PanoramaM-600910-000175 PhysicalKit:920-00020910.2.3-h1RJ45interfaces,USBports,LEDs, SFP+ports
PanoramaM-700910-000270 PhysicalKit:920-00031810.2.3-h1RJ45interfaces,USBports,LEDs, SFP+ports
  1. Cryptographic Module Specification The configurations for this validation are highlighted in Table
  2. Table 2 - Hardware Tested Configuration Module Hardware Firmware Version Distinguishing Features Panorama M-200 Physical Kit: 920-000208 Panorama M-300 Physical Kit: 920-000319 Panorama M-600 Panorama M-700 Approved Mode of Operation The following procedure will initialize the modules into the Approved mode of operation: ● Install physical kit opacity shields and tamper evidence seals according to the Physical Security Policy section. physical kits must be correctly installed to operate in the Approved mode of operation. The tamper evidence seals and opacity shields shall be installed for the module to operate in a Approved mode of operation. ● During initial boot up, break the boot sequence via the console port connection (by pressing the maint button when instructed to do so) to access the main menu. ● Select “Continue.” ● Select the “Set FIPS-CC Mode” option to initialize the Approved mode. ● Select “Enable FIPS-CC Mode”. ● When prompted, select “Reboot” and the module will re-initialize and continue into the Approved mode of operation (FIPS-CC mode). ● The module will reboot. ● In FIPS-CC mode, the console port is available only as a status output port. ● Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module o Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten The module will automatically indicate the Approved mode of operation in the following manner: ● Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session. ● Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port. ● The module will display “FIPS-CC” at all times in the status bar at the bottom of the web interface. ● The module will display “fips-cc” when “show system info” is entered via the CLI Should one or more power-up self-tests fail, the Approved mode of operation will not be achieved. Feedback will consist of: © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 5
Page 6
Page 7
CAVP CertAlgorithmand StandardMode/MethodDescription/KeySize(s)/Key Strength(s)Use/Function
A2165Conditioning Component AES-CBC-MACSP 800-90BAES-CBC-MAC128bitsVettedconditioningcomponentforESV Cert.#E65
A2165VettedconditioningcomponentforESV Cert.#E66
A2518VettedconditioningcomponentforESV Cert.#E64
A2906AES-CBC[SP 800-38A]CBC128,192and256bitsEncryption Decryption
A2906AES-CFB128[SP 800-38A]CFB128128bitsEncryption Decryption
A2906AES-CTR[SP800-38A]CTR128,192and256bitsEncryption Decryption
A2906AES-GCMGCM**128and256bitsEncryption

Convert the M-600/M-700 appliance from PAN-DB mode to the Panorama Manager mode:

Page 8
[SP800-38D]Decryption
A2906CounterDRBG [SP800-90Arev1]CounterDRBGAES256bitswithDerivationFunctionEnabledRandomBitGenerator
A2906ECDSAKeyGen (FIPS186-4)ECDSAKeyGenP-256,P-384,P-521KeyGeneration
A2906ECDSAKeyVer(FIPS 186-4)ECDSAKeyVerP-256,P-384,P-521PublicKeyValidation
A2906ECDSASigGen (FIPS186-4)ECDSASigGenP-256,P-384,P-521withSHA2-224,SHA2-256, SHA2-384,andSHA2-512SignatureGeneration
A2906ECDSASigVer(FIPS 186-4)ECDSASigVerP-256,P-384,P-521withSHA-1,SHA2-224, SHA2-256,SHA2-384,andSHA2-512SignatureVerification
A2906HMAC-SHA-1[FIPS 198-1]HMACHMAC-SHA-1withλ=96,160Authenticationforprotocols
A2906HMAC-SHA2-224 [FIPS198-1]HMACHMAC-SHA2-224withλ=224Authenticationforprotocols
A2906HMAC-SHA2-256 [FIPS198-1]HMACHMAC-SHA2-256withλ=256Authenticationforprotocols
A2906HMAC-SHA2-384 [FIPS198-1]HMACHMAC-SHA2-384withλ=384Authenticationforprotocols
A2906HMAC-SHA2-512 [FIPS198-1]HMACHMAC-SHA2-512withλ=512Authenticationforprotocols
A2906KAS-ECC-SSC Sp800-56Ar3KASEphemeralUnifiedModel:P-256/P-384/P-521KeyExchange
A2906KAS-FFC-SSCSP 800-56Ar3KASdhEphem:MODP-2048KeyExchange
A2906KDFSNMP[SP 800-135rev1](CVL)SNMPv3KDFEngineID: 80001F88043030303030 343935323630SNMPv3
A2906KDFSSH[SP 800-135rev1](CVL)SSHv2KDFSHA-1,SHA2-256, SHA2-512SSH
A2906KDFTLS[SP 800-135rev1](CVL)TLS1.2KDFTLSv1.2HashAlgorithm:SHA2-256,SHA2-384TLS
SA2906RSA KeyGen (FIPS186-4)RSA KeyGen (FIPS186-4)2048,3072,and4096bitsKeyPairGeneration
A2906RSA SigGen (FIPS186-4)RSA SigGen (FIPS186-4)(ANSIX9.31,RSASSA-PKCS1_v1-5, RSASSA-PSS):2048,3072,and4096-bitwith hashes256/384/512SSignatureGeneration
A2906RSA SigVer (FIPS186-4)RSA SigVer (FIPS186-4)(ANSIX9.31,RSASSA-PKCS1_v1-5, RSASSA-PSS):2048,3072,4096-bit(perIGC.F) withhashesSHA-1/224+++/256/384/512 (SignatureVerification) +++ThisHashalgorithmisnotsupportedfor ANSIX9.31SignatureVerification
A2906SHA-1[FIPS180-4]SHASHA-1DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC)
A2906SHA2-224[FIPS 180-4]SHA2SHA-224DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC)
A2906SHA2-256[FIPS 180-4]SHA2SHA-256DigitalSignature Generation/Verification
Table, extracted as text (did not parse into structured rows)
Counter DRBG A2906                            Counter DRBG    AES 256 bits with Derivation Function Enabled     Random Bit Generator ECDSA KeyGen                                                                            Key Generation ECDSA KeyVer (FIPS                                                                      Public Key Validation HMAC            HMAC-SHA-1 with λ=96, 160                         Authentication for protocols HMAC                                                              Authentication for protocols HMAC            HMAC-SHA2-256 with λ=256                          Authentication for protocols HMAC            HMAC-SHA2-384 with λ=384                          Authentication for protocols HMAC            HMAC-SHA2-512 with λ=512                          Authentication for protocols A2906                                                                                              Key Exchange Engine ID: KDF SNMP [SP A2906                             SSHv2 KDF                                                         SSH +++ This Hash algorithm is not supported for ANSI X9.31 Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) © 2024 Palo Alto Networks, Inc.                                                              Panorama HW 10.2 Security Policy 8
Page 9
Non-DigitalSignatureApplications (e.g.componentofHMAC)
A2906SHA2-384[FIPS 180-4]SHA2SHA-384DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC)
A2906SHA2-512[FIPS 180-4]SHA2SHA-512DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC)
A2906SafePrimesKey Generation[RFC 3526]SafePrimesKey GenerationMODP-2048SafePrimesKeyGeneration
A2906SafePrimesKey Verification[RFC 3526]SafePrimesKey VerificationMODP-2048SafePrimesKeyVerification
AESCert.# A2906and HMAC Cert.# A2906KTS [SP800-38F]SP800-38A,FIPS 198-1,andSP 800-38F.KTS(key wrappingand unwrapping)perIG D.G.128,192,and256-bitkeysproviding128,192,or 256bitsofencryptionstrengthKeyWrapping
AES-GCM Cert.# A2906KTS [SP800-38F]SP800-38DandSP 800-38F.KTS(key wrappingand unwrapping)perIG D.G.128and256-bitkeysproviding128or256bits ofencryptionstrengthKeyWrapping
ESVCert. #E64SP800-90BESVPaloAltoNetworksDRNGEntropySourceEntropy
ESVCert. #E65SP800-90BESVPaloAltoNetworksDRNGEntropySourceEntropy
ESVCert. #E66SP800-90BESVPaloAltoNetworksDRNGEntropySourceEntropy
KAS-ECC-S SCCert. #A2906, KDFSSH Cert. #A2906KAS[SP 800-56Arev3]SP800-56Arev3. KAS-ECCperIGD.F Scenario2path(2).P-256,P-384,andP-521curvesproviding128, 192,or256bitsofencryptionstrengthKeyExchangewithprotocolKDF
KAS-ECC-S SCCert. #A2906, KDFTLS Cert. #A2906KAS[SP 800-56Arev3]SP800-56Arev3. KAS-ECCperIGD.F Scenario2path(2).P-256,P-384,andP-521curvesproviding128, 192,or256bitsofencryptionstrengthKeyExchangewithprotocolKDF
KAS-FFC-S SCCert. #A2906, KDFSSH Cert. #A2906KAS[SP 800-56Arev3]SP800-56Arev3. KAS-FFCperIGD.F Scenario2path(2).2048-bitkeyproviding112bitsofencryption strengthKeyExchangewithprotocolKDF
KAS-FFC-S SCCert. #A2906, KDFTLSKAS[SP 800-56Arev3]SP800-56Arev3. KAS-FFCperIGD.F Scenario2path(2).2048-bitkeyproviding112bitsofencryption strengthKeyExchangewithprotocolKDF
Table, extracted as text (did not parse into structured rows)
Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Safe Primes Key Safe Primes Key Safe Primes Key Safe Primes Key A2906 and [SP 800-38F]        wrapping and           256 bits of encryption strength unwrapping) per IG D.G. SP 800-38D and SP KTS                                        128 and 256-bit keys providing 128 or 256 bits Cert. #                           wrapping and                                                               Key Wrapping A2906                             unwrapping) per IG D.G. SP 800-90B          ESV                    Palo Alto Networks DRNG Entropy Source              Entropy SP 800-90B          ESV                    Palo Alto Networks DRNG Entropy Source              Entropy SP 800-90B          ESV                    Palo Alto Networks DRNG Entropy Source              Entropy SC Cert. KAS-ECC per IG D.F                                                         Key Exchange with protocol KDF KDF SSH       800-56Arev3]                               192, or 256 bits of encryption strength Scenario 2 path (2). SC Cert. KAS-ECC per IG D.F                                                         Key Exchange with protocol KDF KDF TLS       800-56Arev3]                               192, or 256 bits of encryption strength Scenario 2 path (2). SC Cert. #A2906,       KAS [SP                                    2048-bit key providing 112 bits of encryption KAS-FFC per IG D.F                                                         Key Exchange with protocol KDF Scenario 2 path (2). SC Cert.      KAS [SP                                    2048-bit key providing 112 bits of encryption KAS-FFC per IG D.F                                                         Key Exchange with protocol KDF Scenario 2 path (2). KDF TLS © 2024 Palo Alto Networks, Inc.                                                                      Panorama HW 10.2 Security Policy 9
Page 10
Cert. #A2906
Vendor AffirmedCKG (SP800-133rev2)Section5.1,Section 5.2CryptographicKey Generation;SP800- 133andIGD.I.KeyGeneration Note:Seedsusedforasymmetrickey pairgenerationareproducedusingthe unmodified/directoutputoftheDRBG
Table, extracted as text (did not parse into structured rows)
Key Generation Cryptographic Key Vendor      CKG                 Section 5.1, Section                                            Note: Seeds used for asymmetric key Generation; SP 800Affirmed    (SP 800-133rev2)    5.2                                                             pair generation are produced using the
133 and IG D.I.

unmodified/direct output of the DRBG The module is compliant to IG C.H: GCM is used in the context of TLS and SSH:

Page 11

Table 4 - Supported Protocols in the Approved Mode TLSv1.2 SSHv2 SNMPv3 *Note: these protocols were not reviewed or tested by the CMVP or CAVP. Module Diagrams Figures 1 - 8 depict the modules and their interfaces. Please refer to the appendices for depictions of the modules with the physical kits installed. Figure 1 - M-200 Front Figure 2 - M-200 Rear Figure 3 - M-300 Front Figure 4 - M-300 Rear Figure 5 - M-600 Front © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 11

Page 12
PhysicalInterfaceLogicalInterfaceDatathatpassesoverport/interface
LEDStatusoutputModulestatusviaLEDindicators
PowerPowerN/A
RJ45ConsoleStatusoutputSelf-testoutput

Figure 6 - M-600 Rear Figure 7 - M-700 Front Figure 8 - M-700 Rear 3. Cryptographic Module Interfaces The modules are multi-chip standalone modules with ports and interfaces as shown below. The modules do not implement a control output interface. Table 5 - Ports and Interfaces Physical Interface Logical Interface Data that passes over port/interface LED Status output Module status via LED indicators RJ45 Console Status output Self-test output © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 12

Page 13
RJ45EthernetDatainput,controlinput,controloutput, dataoutput,statusoutputTLS,SSH
SFP+ (M-600,M-700)Datainput,controlinput,dataoutput, statusoutputTLS
RoleServiceInputOutput
COShowVersionQuerymoduleforversionModuleprovidesversion
COSystemProvisioningConfiguringandmanaging systemconfigurations(e.g.,IP address,systemtime,etc.)via CLIorWebUIConfirmationofservicevia ConfigurationLogs
CO,UserAccesswebportalConnecttowebportalfromTLS client.Confirmationofservicevia ConfigurationLogs
CO,UserAccessCLIConnecttoSSHserverfromSSH clientConfirmationofservicevia ConfigurationLogs
COPanoramaFirmwareUpdateLoadingnewimageMessageoutputnotingversion updatedsuccessfullyviaSystem Logs
COPanoramaManagerSetupConfiguringandmanaging Managerconfigurations(e.g., HTTPS,NTP,etc.)viaCLIor WebUIConfirmationofservicevia ConfigurationLogs
COManagePanorama AdministrativeAccessConfiguringandmanaging Administrativeconfigurations (e.g.,creatinguseraccounts, settingauthenticationmethod, etc.)viaCLIorWebUIConfirmationofservicevia ConfigurationLogs
COConfigureHighAvailabilityConfiguringandmanagingHigh Availability(HA)configuration viaCLIorWebUIConfirmationofservicevia ConfigurationLogs

RJ45 Ethernet Data input, control input, control output, TLS, SSH data output, status output 4. Roles, Services, and Authentication Assumption of Roles The module supports distinct operator roles. The cryptographic module in Panorama mode, Management-Only mode, or PAN-DB mode enforces the separation of roles using unique authentication credentials associated with operator accounts. The Log Collector mode only supports one role, the Crypto-Officer (CO) role. The module supports concurrent operators. The module does not provide a maintenance role or bypass capability. Table 6 – Roles, Service Commands, Input and Output Query module for version Module provides version CO Show Version Configuring and managing Confirmation of service via System Provisioning CLI or WebUI Access web portal Connect to web portal from TLS Confirmation of service via Access CLI Connect to SSH server from SSH Confirmation of service via Panorama Firmware Update Loading new image Message output noting version CO updated successfully via System Panorama Manager Setup Configuring and managing Confirmation of service via Manager configurations (e.g., Configuration Logs Manage Panorama Configuring and managing Confirmation of service via Administrative Access Administrative configurations Configuration Logs CO (e.g., creating user accounts, setting authentication method, Configure High Availability Configuring and managing High Confirmation of service via via CLI or WebUI © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 13

Page 14
COPanoramaCertificate ManagementConfiguringandmanaging certificatesviaCLIorWebUIConfirmationofservicevia ConfigurationLogs
COPanoramaLogSettingConfiguringandmanaginglog settingsviaCLIorWebUIConfirmationofservicevia ConfigurationLogs
COPanoramaServerProfilesConfiguringandmanaging Serverconfigurations(e.g. SNMP,etc.)viaCLIorWebUIConfirmationofservicevia ConfigurationLogs
COSetupManagedDevicesand DeploymentConfiguringandmanaging ManagedDevicesconfigurations (e.g.,Versions,Licenses,etc.)via CLIorWebUIConfirmationofservicevia ConfigurationLogs
COConfigureManagedLog CollectorsConfiguringandmanaging ManagedLogCollectors configurationsviaCLIorWebUIConfirmationofservicevia ConfigurationLogs
CO, Unauthentica tedZeroizeZeroizefromCLIZeroizationIndicator
CO,User, Unauthentica tedSelf-TestRunself-testviaCLIorWebUIOutputresultsviaSystemLogs
CO,UserShowStatusShowstatusviaCLIorWebUIFIPS-CCModeIndicator
CO,UserSystemAuditViewsystemauditrecordsvia CLIorWebUIAuditrecordsviaSystemLogs
CO,UserMonitorSystemStatusandLogsViewsystemstatusrecordsvia CLIorWebUISystemstatusviaSystemLogs
COPanoramaLogCollectorSetupConfiguringandmanagingLog CollectorsconfigurationsviaCLIConfirmationofservicevia ConfigurationLogs
COPanoramaPan-DBSetupConfiguringandmanaging Pan-DBURLconfigurationsvia CLIConfirmationofservicevia ConfigurationLogs
COManagePan-DBAdministrative AccessConfiguringandmanaging AdministratorpasswordviaCLIConfirmationofservicevia ConfigurationLogs
RoleAuthenticationMethodAuthenticationStrength
COMemorizedSecret(Unique Username/password)and/or Single-FactorCryptographic Software(certificatecommon name/publickey-based authentication)Password-based Minimumlengthiseight1(8)characters(95possiblecharacters). Theprobabilitythatarandomattemptwillsucceedorafalse acceptancewilloccuris1/(958)whichislessthan1/1,000,000. Theprobabilityofsuccessfullyauthenticatingtothemodule withinoneminuteis10/(958),whichislessthan1/100,000. The module’sconfigurationsupportsatmosttenfailedattemptsto authenticateinaone-minuteperiod.
Table, extracted as text (did not parse into structured rows)
Panorama Certificate               Configuring and managing             Confirmation of service via Management                         certificates via CLI or WebUI        Configuration Logs Panorama Log Setting               Configuring and managing log Confirmation of service via settings via CLI or WebUI            Configuration Logs Panorama Server Profiles           Configuring and managing             Confirmation of service via CO                                          Server configurations (e.g.          Configuration Logs Setup Managed Devices and          Configuring and managing             Confirmation of service via Deployment                         Managed Devices configurations Configuration Logs Configure Managed Log              Configuring and managing             Confirmation of service via CO       Collectors                         Managed Log Collectors               Configuration Logs CO,      Zeroize                            Zeroize from CLI                     Zeroization Indicator CO, User, Self-Test                            Run self-test via CLI or WebUI     Output results via System Logs Show Status                        Show status via CLI or WebUI       FIPS-CC Mode Indicator System Audit                   View system audit records via Audit records via System Logs Monitor System Status and Logs View system status records via System status via System Logs Panorama Log Collector Setup   Configuring and managing Log Confirmation of service via Collectors configurations via CLI Configuration Logs Panorama Pan-DB Setup          Configuring and managing          Confirmation of service via CO                                      Pan-DB URL configurations via Configuration Logs Manage Pan-DB Administrative Configuring and managing            Confirmation of service via Access                         Administrator password via CLI Configuration Logs Table 7 - Roles and Authentication Role          Authentication Method                        Authentication Strength Username/password) and/or       Minimum length is eight1 (8) characters (95 possible characters). Single-Factor Cryptographic     The probability that a random attempt will succeed or a false Software (certificate common    acceptance will occur is 1/(958) which is less than 1/1,000,000. name / public key-based         The probability of successfully authenticating to the module authentication)                 within one minute is 10/(958), which is less than 1/100,000. The module’s configuration supports at most ten failed attempts to authenticate in a one-minute period. In FIPS-CC Mode, the module checks and enforces the minimum password length of eight (8) as specified in SP 800-63B. Passwords are securely stored hashed with salt value, with very restricted access control, and rate limiting mechanism for authentication attempts. © 2024 Palo Alto Networks, Inc.                                                          Panorama HW 10.2 Security Policy 14
Page 15
Certificate/Publickey-based Thesecuritymodulessupportpublic-keybasedauthentication usingRSA2048andcertificate-basedauthenticationusingRSA 2048,RSA3072,RSA4096,ECDSAP-256,P-384,orP-521. Theminimumequivalentstrengthsupportedis112bits. The probabilitythatarandomattemptwillsucceedis1/(2112)whichis lessthan1/1,000,000. Theprobabilityofsuccessfully authenticatingtothemodulewithinaoneminuteperiodis 10/(2112),whichislessthan1/100,000. ThemoduleinFIPS-CC modeallowsatmost10failedattemptsbeforealockoutoccurs.
UserMemorizedSecret(Unique Username/password)and/or Single-FactorCryptographic Software(certificatecommon name/publickey-based authentication)

Certificate/Public key-based The security modules support public-key based authentication Memorized Secret (Unique 2048, RSA 3072, RSA 4096, ECDSA P-256, P-384, or P-521. Single-Factor Cryptographic The minimum equivalent strength supported is 112 bits. The Software (certificate common probability that a random attempt will succeed is 1/(2112) which is User less than 1/1,000,000. The probability of successfully name / public key-based authentication) authenticating to the module within a one minute period is 10/(2112), which is less than 1/100,000. The module in FIPS-CC mode allows at most 10 failed attempts before a lockout occurs. Access Control Policy While in the Approved mode of operation all authenticated services and CSPs are accessed via authenticated SSH or TLS sessions. Access is restricted to authenticated operators only and no interface is provided to modify the public or private key. SNMPv3 authentication is supported but is not a method of module administration and does not allow read/write access of CSPs. Approved and allowed algorithms, relevant CSP and public keys related to these protocols are used to access the following services. CSP access by services is further described in the following tables. Additional service information and administrator guidance for Panorama can be found at https://docs.paloaltonetworks.com/. The Crypto-Officer may access all services, and through the “management of administrative access” service may define multiple Crypto-Officer roles with limited services. The User role provides read-only access to the System Audit service. When configured in the default mode, Panorama Manager provides services via web-browser based interface and a command line interface (CLI). For the Panorama Log Collector mode and PAN-DB mode, only the CLI is available for management. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 15

Page 16
ServiceDescriptionApprovedSecurityFunctionsKeysand/orSSPsRolesAccessrightsto Keysand/orSSPsIndicator
ShowVersionQuerythemoduletodisplay theversionN/AN/ACON/AVersiondisplayedvia SystemLogs/CLI/UI
SystemProvisioningPerformpanorama licensing,diagnostics, debugfunctions,manage Panoramasupport informationandswitch betweenPanorama Management-only,and Loggermodes. (Panoramaor Management-Only Mode)N/AN/ACON/ASystemand Configurationlogs
AccesswebportalConnecttomodule’sweb portaltoinvokeservices. (Panoramaor Management-OnlyMode)RSASigVer(186-4)CACertificatesCOG/R/E/WSystemLogs
RSASigVer(186-4)RSAPublicKeysG/R/E/W
ECDSASigVer(186-4)ECDSAPublicKeysG/R/E/W
KASKDFTLS(CVL)TLSPre-Master SecretG/E/Z
KDFTLS(CVL)TLSMasterSecretG/E/Z
CKG, ECDSAKeyGen (FIPS186-4), ECDSAKeyVer (FIPS186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimesKey Generation,Safe PrimesKey VerificationTLSDHE/ECDHE PrivateComponentsG/E/Z
TLSDHE/ECDHE PublicComponentsG/E/Z
KTSHMAC-SHA2-256 HMAC-SHA2-384TLSHMACKeysG/E/Z
AES-CBCTLSEncryptionKeysG/E/Z
KTSAES-GCMTLSEncryptionKeysG/E/Z
CounterDRBG,ESVDRBGSeed DRBGV DRBGKey EntropyInputStringG/E
Table, extracted as text (did not parse into structured rows)
SSP Access Rights The table below defines the relationship between access to CSPs and the different module services. The modes of access shown in the table are defined as: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Table 8 - Approved Services Service                Description                Approved Security Functions         Keys and/or SSPs      Roles   Access rights to          Indicator Keys and/or SSPs Show Version            Query the module to display N/A                                      N/A                    CO       N/A                Version displayed via the version                                                                                                             System Logs / CLI / UI Perform panorama debug functions, manage Panorama support information and switch between Panorama                                                                                                        System and System Provisioning                                  N/A                                     N/A                   CO        N/A Logger modes. (Panorama or Access web portal       Connect to module’s web      RSA SigVer (186-4)                      CA Certificates        CO       G/R/E/W            System Logs portal to invoke services. RSA SigVer (186-4)                      RSA Public Keys                 G/R/E/W (Panorama or                 ECDSA SigVer (186-4)                    ECDSA Public Keys               G/R/E/W CKG,              TLS DHE/ECDHE                   G/E/Z ECDSA KeyGen      Private Components (FIPS 186-4), ECDSA KeyVer (FIPS 186-4), Safe Primes Key    Public Components Primes Key KTS                                     TLS HMAC Keys                   G/E/Z AES-CBC            TLS Encryption Keys             G/E/Z KTS                  AES-GCM            TLS Encryption Keys             G/E/Z Counter DRBG, ESV                       DRBG Seed                       G/E DRBG V DRBG Key Entropy Input String © 2024 Palo Alto Networks, Inc.                                                                                      Panorama HW 10.2 Security Policy 16
Page 17

AccessCLI PanoramaFirmware Update PanoramaManagerSetup

Connecttomodule’sCLIvia SSH Downloadandinstall firmwareupdates Presentsconfiguration optionsformanagement interfacesand communicationforpeer services(e.g.,SNMP, RADIUS). Import,Export,Save,Load, revertandvalidate Panoramaconfigurations andstaterole (Panoramaor Management-OnlyMode)

KTS KTS KAS CounterDRBG,ESV RSASigVer(FIPS186-4) CKG RSAKeyGen(FIPS186-4) RSASigGen(FIPS186-4) CKG ECDSAKeyGen (FIPS186-4) ECDSASigGen (FIPS186-4) RSASigVer(FIPS186-4) ECDSASigVer(FIPS186-4) KDFSNMP(CVL) KDFSNMP(CVL) HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 AES-CFB128 RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) KAS KTS

HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 AES-CBC AES-CTR AES-GCM KDFSSH(CVL) KAS-ECC-SSC KAS-FFC-SSC SafePrimesKey Generation SafePrimesKey Verification KDFTLS(CVL) KDFTLS(CVL) CKG, ECDSAKeyGen (FIPS186-4), ECDSAKeyVer (FIPS186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimesKey Generation,Safe PrimesKey Verification HMAC-SHA2-256 HMAC-SHA2-384 AES-CBC

SSHSession AuthenticationKeys SSHSession EncryptionKeys SSHDHE/ECDHE PrivateComponents SSHDHE/ECDHE PublicComponents DRBGSeed DRBGV DRBGKey EntropyInputString PublicKeyfor FirmwareLoadTest RSAPrivateKeys ECDSAPrivateKeys RSAPublicKeys ECDSAPublicKeys SNMPv3 AuthenticationSecret SNMPv3Privacy Secret SNMPv3 AuthenticationKey SNMPv3SessionKey CACertificates TLSPre-Master Secret TLSMasterSecret TLSDHE/ECDHE PrivateComponents TLSDHE/ECDHE PublicComponents TLSHMACKeys TLSEncryptionKeys

CO,User CO CO

G/E/Z G/E/Z G/E/Z G/E/Z G/E/R/W/Z G/E W/E G/W/E G/W/E G/R/E/W G/R/E/W W/E W/E G/E/Z G/E/Z G/R/E/W G/E/Z G/E/Z G/E/Z G/E/R/W/Z G/E/Z G/E/Z

SystemLogs Systemand Configurationlogs Systemand Configurationlogs

Table, extracted as text (did not parse into structured rows)
Access CLI               Connect to module’s CLI via KTS                 HMAC-SHA-1    SSH Session                  CO, User   G/E/Z       System Logs AES-CTR            Encryption Keys Private Components Safe Primes Key Safe Primes Key Counter DRBG, ESV                      DRBG Seed                          G/E DRBG V DRBG Key Entropy Input String Panorama Firmware        Download and install        RSA SigVer (FIPS 186-4)                Public Key for          CO         W/E         System and Update                   firmware updates                                                   Firmware Load Test                             Configuration logs Panorama Manager Setup Presents configuration        CKG                                    RSA Private Keys        CO         G/W/E       System and options for management        RSA KeyGen (FIPS 186-4)                                                               Configuration logs interfaces and                RSA SigGen (FIPS 186-4) communication for peer CKG                                    ECDSA Private Keys                 G/W/E ECDSA KeyGen ( FIPS 186-4) ECDSA SigGen revert and validate (FIPS 186-4) Panorama configurations and state role                RSA SigVer (FIPS 186-4)                RSA Public Keys                    G/R/E/W ECDSA SigVer (FIPS 186-4)              ECDSA Public Keys                  G/R/E/W (Panorama or Management-Only Mode)       KDF SNMP (CVL)                         SNMPv3                             W/E Authentication Secret RSA SigVer (FIPS 186-4)               CA Certificates                    G/R/E/W ECDSA SigVer (FIPS 186-4) KAS                  KDF TLS (CVL)     TLS Pre-Master                     G/E/Z CKG,               TLS DHE/ECDHE                      G/E/Z ECDSA KeyGen       Private Components (FIPS 186-4), TLS DHE/ECDHE                      G/E/R/W/Z ECDSA KeyVer Public Components (FIPS 186-4), Safe Primes Key Primes Key AES-CBC            TLS Encryption Keys                G/E/Z © 2024 Palo Alto Networks, Inc.                                                                                       Panorama HW 10.2 Security Policy 17
Page 18
KTSAES-GCMTLSEncryptionKeysG/E/Z
KTSHMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512SSHSession AuthenticationKeysG/E/Z
AES-CBC, AES-CTRSSHSession EncryptionKeysG/E/Z
KTSAES-GCM
KASKDFSSH(CVL) KAS-ECC-SSC KAS-FFC-SSC SafePrimesKey Generation,Safe PrimesKey VerificationSSHDHE/ECDHE PrivateComponentsG/E/Z
SSHDHE/ECDHE PublicComponentsG/E/R/W/Z
CounterDRBG,ESVDRBGSeed DRBGV DRBGKey EntropyInputStringCOG/ESystemand ConfigurationLogs
ManagePanorama AdministrativeAccessDefineaccesscontrol methodsviaadminprofiles, configureadministrators andpasswordprofiles Configurelocaluser database,authentication profiles,sequenceof methodsandaccess domains. (Panorama, Management-Only,orLog CollectorMode)N/ACO,UserPasswordCOG/E/WSystemand Configurationlogs
RSASigVer(FIPS186-4)SSHClientPublicKeyW/E
RSASigVer(FIPS186-4) ECDSASigVer(FIPS186-4)SSHHostPublicKeyG/R/E/W
ConfigureHigh AvailabilityConfigureHighAvailability communicationsettings (Panoramaor Management-OnlyMode)RSASigVer(FIPS186-4)RSAPublicKeyCOG/R/E/WConfigurationLogs
ECDSASigVer(FIPS186-4)ECDSAPublicKeyG/R/E/W
PanoramaCertificate ManagementManageRSA/ECDSA certificatesandprivate keys,certificateprofiles, revocationstatus,and usage;showstatus.ECDSASigGen (FIPS186-4) RSASigGen (FIPS186-4)RSAPrivateKeys ECDSAPrivateKeysCOG/R/W/ESystemand Configurationlogs
Table, extracted as text (did not parse into structured rows)
AES-CBC,           SSH Session                    G/E/Z KAS                 KDF SSH (CVL)      SSH DHE/ECDHE                  G/E/Z Safe Primes Key Primes Key SSH DHE/ECDHE                  G/E/R/W/Z Public Components Counter DRBG, ESV                      DRBG Seed               CO     G/E         System and DRBG V                                     Configuration Logs DRBG Key Entropy Input String Manage Panorama         Define access control       N/A                                      CO, User Password       CO     G/E/W       System and Administrative Access   methods via admin profiles,                                                                                     Configuration logs configure administrators Configure local user profiles, sequence of       RSA SigVer (FIPS 186-4)                  SSH Client Public Key          W/E methods and access Management-Only, or Log Collector Mode)               RSA SigVer (FIPS 186-4)                SSH Host Public Key            G/R/E/W ECDSA SigVer (FIPS 186-4) Configure High          Configure High Availability   RSA SigVer (FIPS 186-4)                RSA Public Key          CO     G/R/E/W     Configuration Logs Availability            communication settings (Panorama or ECDSA SigVer (FIPS 186-4)              ECDSA Public Key               G/R/E/W Panorama Certificate    Manage RSA/ECDSA              ECDSA SigGen                           RSA Private Keys        CO     G/R/W/E     System and Management              certificates and private      (FIPS 186-4)                           ECDSA Private Keys                         Configuration logs keys, certificate profiles,   RSA SigGen revocation status, and        (FIPS 186-4) usage; show status. © 2024 Palo Alto Networks, Inc.                                                                                       Panorama HW 10.2 Security Policy 18
Page 19
(Panorama, Management-Only,orLog CollectorMode)ECDSASigVer (FIPS186-4) RSASigVer (FIPS186-4) CounterDRBG,ESVRSAPublicKeys ECDSAPublicKeys DRBGSeed DRBGV DRBGKey EntropyInputStringG/R/W/E G/E
PanoramaLogSettingConfigurelogforwarding (Panoramaor Management-OnlyMode)N/AN/ACON/AConfigurationLogs
PanoramaServerProfilesConfigurecommunication parametersandinformation forpeerservers (Panoramaor Management-OnlyMode)KDFSNMP(CVL)SNMPv3 AuthenticationSecretCOW/ESystemLogs
KDFSNMP(CVL)SNMPv3Privacy SecretW/E
HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512SNMPv3 AuthenticationKeyG/E/Z
AES-CFB128SNMPv3SessionKeyG/E/Z
SetupManagedDevices andDeploymentSet-upanddefinemanaged devices,devicegroupsfor firewalls Configuredevice deploymentapplications andlicenses Viewcurrentdeployment informationonthemanaged firewalls.Italsoallowsyou tomanagefirmware versionsandschedule updatesonthemanaged firewallsandmanagedlog collectors. (Panoramaor Management-OnlyMode)N/AN/ACON/AConfigurationLogs
ConfigureManagedLog CollectorsSetupandmanageother LogCollectormanagement, communicationandstorage settings Viewcurrentdeployment informationonthemanaged LogCollectors.Italsoallows youtomanagefirmware versionsandschedule updatesonmanagedlog collectors. (Panoramaor Management-OnlyMode)N/ACO,UserPasswordCOG/E/WSystemand Configurationlogs
ZeroizeZeroizeallSSPsN/AAllSSPsCOZZeroizationIndicator
Self-TestRunpowerupself-testson demandbypowercycling themodule.N/AFirmwareIntegrity VerificationKeyCO,UserESystemLogs
Table, extracted as text (did not parse into structured rows)
(Panorama,                      ECDSA SigVer        RSA Public Keys                   G/R/W/E Management-Only, or Log         (FIPS 186-4)        ECDSA Public Keys Collector Mode)                 RSA SigVer (FIPS 186-4) Counter DRBG, ESV   DRBG Seed                         G/E DRBG V DRBG Key Entropy Input String Panorama Log Setting       Configure log forwarding        N/A                 N/A                    CO         N/A       Configuration Logs (Panorama or Panorama Server Profiles   Configure communication KDF SNMP (CVL)              SNMPv3                CO          W/E       System Logs parameters and information                          Authentication Secret for peer servers KDF SNMP (CVL)           SNMPv3 Privacy                    W/E (Panorama or Setup Managed Devices      Set-up and define managed N/A                       N/A                    CO         N/A       Configuration Logs and Deployment             devices, device groups for Configure device deployment applications and licenses View current deployment information on the managed firewalls. It also allows you to manage firmware versions and schedule updates on the managed firewalls and managed log (Panorama or Configure Managed Log      Setup and manage other         N/A                  CO, User Password      CO         G/E/W     System and Collectors                 Log Collector management,                                                                       Configuration logs communication and storage View current deployment information on the managed Log Collectors. It also allows you to manage firmware versions and schedule updates on managed log (Panorama or Zeroize                    Zeroize all SSPs                N/A                 All SSPs               CO         Z         Zeroization Indicator Self-Test                  Run power up self-tests on      N/A                 Firmware Integrity     CO, User   E         System Logs demand by power cycling                             Verification Key the module. © 2024 Palo Alto Networks, Inc.                                                                         Panorama HW 10.2 Security Policy 19
Page 20
ShowStatusViewstatusofthemoduleN/AN/ACO,UserN/AFIPS-CCModeIndicator
SystemAuditAllowsreviewoflimited configurationandsystem statusviaSNMPv3,logs, dashboard,showstatus,and configurationscreens. COOnly:Provides configurationcommit capability. (Panorama, Management-Only,or PAN-DBMode)N/AN/ACO,UserN/ASystemLogs
MonitorSystemStatusand LogsReviewsystemstatusvia thepanoramasystemCLI, dashboardandlogs;show status. (Panoramaor Management-OnlyMode)N/AN/ACO,UserN/ASystemLogs
PanoramaLogCollector SetupPresentsconfiguration optionsformanagement interfacesand communicationforpeer services Import,Export,Save,Load, revertandvalidate Panoramaconfigurations andstate. (LogCollectorModeonly)CKG RSAKeyGen(FIPS186-4) RSASigGen(FIPS186-4)RSAPrivateKeysCOG/W/ESystemand Configurationlogs
CKG ECDSAKeyGen (FIPS186-4) ECDSASigGen (FIPS186-4)ECDSAPrivateKeysG/W/E
RSASigVer(FIPS186-4)RSAPublicKeysG/R/E/W
ECDSASigVer(FIPS186-4)ECDSAPublicKeysG/R/E/W
KASKDFTLS(CVL)TLSPre-Master SecretG/E/Z
KDFTLS(CVL)TLSMasterSecretG/E/Z
CKG, ECDSAKeyGen (FIPS186-4), ECDSAKeyVer (FIPS186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimesKey Generation,Safe PrimesKey VerificationTLSDHE/ECDHE PrivateComponentsG/E/Z
TLSDHE/ECDHE PublicComponentsG/E/R/W/Z
Table, extracted as text (did not parse into structured rows)
Show Status               View status of the module     N/A                                    N/A                  CO, User   N/A         FIPS-CC Mode Indicator System Audit              Allows review of limited    N/A                                      N/A                  CO, User   N/A         System Logs configuration and system status via SNMPv3, logs, configuration screens. configuration commit PAN-DB Mode) Monitor System Status and Review system status via      N/A                                    N/A                  CO, User   N/A         System Logs Logs                      the panorama system CLI, CKG                                    RSA Private Keys     CO         G/W/E       System and Panorama Log Collector    Presents configuration        RSA KeyGen (FIPS 186-4)                                                            Configuration logs Setup                     options for management        RSA SigGen (FIPS 186-4) interfaces and communication for peer revert and validate           ECDSA KeyGen Panorama configurations       ( FIPS 186-4) and state.                    ECDSA SigGen (FIPS 186-4) (Log Collector Mode only) RSA SigVer (FIPS 186-4)                RSA Public Keys                 G/R/E/W ECDSA SigVer (FIPS 186-4)              ECDSA Public Keys               G/R/E/W KAS                 KDF TLS (CVL)      TLS Pre-Master                  G/E/Z CKG,              TLS DHE/ECDHE                   G/E/Z ECDSA KeyGen       Private Components (FIPS 186-4), ECDSA KeyVer (FIPS 186-4), Safe Primes Key    Public Components Primes Key © 2024 Palo Alto Networks, Inc.                                                                                       Panorama HW 10.2 Security Policy 20
Page 21
KTSHMAC-SHA2-256 HMAC-SHA2-384 AES-CBCTLSHMACKeys TLSEncryptionKeysG/E/Z G/E/Z
KTSAES-GCMTLSEncryptionKeysG/E/Z
KTSHMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512SSHSession AuthenticationKeysG/E/Z
AES-CBC, AES-CTRSSHSession EncryptionKeysG/E/Z
KTSAES-GCM
KASKDFSSH KAS-ECC-SSC KAS-FFC-SSC SafePrimesKey Generation,Safe PrimesKey VerificationSSHDHE/ECDHE PrivateComponentsG/E/Z
CounterDRBG,ESVDRBGSeed DRBGV DRBGKey EntropyInputStringG/E
PanoramaPan-DBSetupPresentsconfiguration optionsformanagement interfacesand communicationforpeer services Import,Export,Save,Load, revertandvalidate Panoramaconfigurations andstate. (PAN-DBModeonly)KASKDFTLS(CVL)TLSPre-Master SecretCOG/E/ZSystemLogs
KDFTLS(CVL)TLSMasterSecretG/E/Z
Table, extracted as text (did not parse into structured rows)
AES-CBC            TLS Encryption Keys           G/E/Z KTS                 AES-GCM            TLS Encryption Keys           G/E/Z AES-CBC,           SSH Session                   G/E/Z AES-CTR            Encryption Keys KAS                 KDF SSH            SSH DHE/ECDHE                 G/E/Z Private Components Safe Primes Key Primes Key Counter DRBG, ESV                      DRBG Seed                     G/E DRBG V DRBG Key Entropy Input String Panorama Pan-DB Setup   Presents configuration        KAS                 KDF TLS (CVL)      TLS Pre-Master         CO     G/E/Z      System Logs options for management                                               Secret interfaces and communication for peer revert and validate                               KDF TLS (CVL)      TLS Master Secret             G/E/Z Panorama configurations and state. (PAN-DB Mode only) © 2024 Palo Alto Networks, Inc.                                                                                      Panorama HW 10.2 Security Policy 21
Page 22
CKG, ECDSAKeyGen (FIPS186-4), ECDSAKeyVer (FIPS186-4), KAS-ECC-SSC, KAS-FFC-SSC, SafePrimesKey Generation,Safe PrimesKey VerificationTLSDHE/ECDHE PrivateComponents TLSDHE/ECDHE PublicComponentsG/E/Z G/E/R/W/Z
KTSHMAC-SHA2-256 HMAC-SHA2-384TLSHMACKeysG/E/Z
AES-CBCTLSEncryptionKeysG/E/Z
KTSAES-GCMTLSEncryptionKeysG/E/Z
KTSHMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512SSHSession AuthenticationKeysG/E/Z
AES-CBC, AES-CTRSSHSession EncryptionKeysG/E/Z
KTSAES-GCM
KASKDFSSH KAS-ECC-SSC KAS-FFC-SSC SafePrimesKey Generation,Safe PrimesKey VerificationSSHDHE/ECDHE PrivateComponentsG/E/Z
CounterDRBG,ESVDRBGSeed DRBGV DRBGKey EntropyInputStringG/E
Table, extracted as text (did not parse into structured rows)
CKG,              TLS DHE/ECDHE                G/E/Z ECDSA KeyGen       Private Components (FIPS 186-4), ECDSA KeyVer (FIPS 186-4), Safe Primes Key    Public Components Primes Key AES-CBC            TLS Encryption Keys          G/E/Z KTS                 AES-GCM            TLS Encryption Keys          G/E/Z AES-CBC,           SSH Session                  G/E/Z AES-CTR            Encryption Keys KAS                 KDF SSH            SSH DHE/ECDHE                G/E/Z Private Components Safe Primes Key Primes Key Counter DRBG, ESV                      DRBG Seed                    G/E DRBG V DRBG Key Entropy Input String © 2024 Palo Alto Networks, Inc.                                                                 Panorama HW 10.2 Security Policy 22
Page 23

ManagePan-DB AdministrativeAccess

UpdateAdministrator password. (PAN-DBModeonly)

N/A

CO,UserPassword

CO

G/E/W

Systemand Configurationlogs

Manage Pan-DB Update Administrator N/A CO, User Password CO G/E/W System and Administrative Access password. Configuration logs (PAN-DB Mode only) Note: Configuration/System Logs for Approved services above will indicate FIPS-CC mode is enabled and that the service succeeded.

  1. Software/Firmware Security The module performs the Firmware Integrity test by using HMAC-SHA-256 and ECDSA signature verification (HMAC and ECDSA Cert. #A2906) during the Pre-Operational Self-Test. In addition, the module also conducts the firmware load test by using RSA 2048 with SHA-256 (Cert. #A2906) for the new validated firmware to be uploaded into the module. The pre-operational self-tests can be initiated by power cycling the module. When this is performed, the module automatically runs the cryptographic algorithm self-tests in addition to the pre-operational firmware integrity test.
  2. Operational Environment The FIPS 140-3 Area 5 Operational Environment requirements are not applicable because the module contains a non-modifiable operational environment. The operational environment is limited since the module includes a firmware load service to support necessary updates. New firmware versions within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation.
  3. Physical Security Physical Security Mechanisms The multi-chip standalone modules are production quality containing standard passivation. Chip components are protected by an opaque enclosure. There are tamper-evident seals that are applied on the modules by the Crypto-Officer. There are fifteen (15) for the M-200, fifteen (15) for the M-300, twenty-one (21) for the M-600, and twenty-one (21) for the M-700. All unused seals are to be controlled by the Crypto-Officer. The seals prevent removal of the opaque enclosure without evidence. The Crypto-Officer must ensure that the module surface is clean and dry. Tamper evident seals must be pressed firmly onto the adhering surfaces during installation and once applied, the Crypto-Officer shall permit 24 hours of cure time for all tamper evident seals. The seals prevent removal of the opaque enclosure without evidence. The Crypto-Officer should inspect the seals and shields for evidence of tamper every 30 days. If the seals show evidence of tamper, the Crypto-Officer should assume that the modules have been compromised and contact support. Note: For ordering information, see Table 2 for physical kit part numbers and versions. Opacity shields are included in the physical kits. Operator Required Actions The following table provides information regarding the various physical security mechanisms, and their recommended frequency of inspection/test. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 23
Page 24
PhysicalSecurity MechanismRecommendedFrequency ofInspection/TestInspection/TestGuidanceDetails
TamperEvident Seals30days(M-200,M-300)Verifyintegrityoftamper-evidentsealsinthe locationsidentifiedinSection7ofthisSecurityPolicy.
FrontandRear OpacityShields SideRails30days(M-200,M-300)Verifythatopacityshieldsandsiderailshavenot beenloosenedordeformedfromtheiroriginalshape,thereby reducingtheireffectiveness.
TopOverlays30days(M-200,M-300)Verifytopoverlayshavenotbeenremovedor deformed.Alledgesshouldmaintainstrongadhesion characteristics.
TamperEvident Seals30days(M-600,M-700)Verifyintegrityoftamper-evidentsealsinthe locationsspecifiedinSection7ofthisSecurityPolicy.
FrontandRear OpacityShields30days(M-600,M-700)Verifythatthefrontandrearopacityshields havenotbeendeformedfromtheiroriginalshape,thereby reducingtheireffectiveness.
VentOverlays30days(M-600,M-700)Verifythattheventoverlayshavenotbeen removedordeformed.Alledgesshouldmaintainstrongadhesion characteristics.

Table 9 - Physical Security Inspection Guidelines Physical Security Recommended Frequency Inspection/Test Guidance Details Tamper Evident 30 days (M-200, M-300) Verify integrity of tamper-evident seals in the Seals locations identified in Section 7 of this Security Policy.

30 days (M-200, M-300) Verify that opacity shields and side rails have not

Front and Rear been loosened or deformed from their original shape, thereby Opacity Shields reducing their effectiveness. Side Rails Top Overlays 30 days (M-200, M-300) Verify top overlays have not been removed or deformed. All edges should maintain strong adhesion Tamper Evident 30 days (M-600, M-700) Verify integrity of tamper-evident seals in the Seals locations specified in Section 7 of this Security Policy. Front and Rear 30 days (M-600, M-700) Verify that the front and rear opacity shields Opacity Shields have not been deformed from their original shape, thereby reducing their effectiveness. Vent Overlays 30 days (M-600, M-700) Verify that the vent overlays have not been removed or deformed. All edges should maintain strong adhesion Refer to the following sections for instructions on installation and placement of the tamper seals and opacity shields. M-200 Tamper Seal Installation (15 Seals) 1. Replace the top cover with the physical top cover. a. Remove the VOID WARRANTY label and cover screws (replacement label included in the kit). M-200 appliance—Remove the Void Warranty label that covers the left top cover screw then use a Phillips-head screwdriver to remove both screws as indicated in the illustration. b. Simultaneously depress the two (2) release buttons on top of the cover and slide the cover toward the back of the appliance to remove it. c. Slide the top cover (does not have vents) on the appliance until the release buttons click. Reinsert and slide cover into position and secure with the two (2) screws. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 24

Page 25

Figure 9 – M-200: Top Cover Replacement © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 25

Page 26
  1. On the left side of the M-200, firmly apply seven (7) tamper-evident seals as indicated in the illustration. Figure 10 – M-200: Side View Before Rail Installation Install the inner rack mount rail brackets as described in the “M-200 and M-600 Appliance Hardware Reference”. The front rack bracket that you replace in the next step is located on the front inner rails. Figure 11 – M-200: Inner Rack Mount Rail Brackets
  2. Attach the front cover brackets. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 26
Page 27

Replace the front rack-mount brackets (one bracket on each side) that are part of the inner-rack rails with the rack-mount brackets by removing and then reinstalling two screws on each bracket. The handles have standoffs that are used to secure the front cover. Figure 12

Page 28
  1. Attach the physical kit back cover to the back of the appliance. Slide the back cover onto the back of the appliance, insert two M4 x 0.7 x 8mm (one (1) screw on each side), and turn the screws clockwise to secure the cover.
  2. Apply a tamper-evident seal to each location shown in the following M-200 illustrations. Ensure you apply two (2) tamper-evident seals on the power supplies (see seals #14 and #15 on the rear illustration). Before you apply the tamper-evident seals, ensure that the appliance and physical kit surfaces are clean and dry. Firmly press one (1) seal on to each of the locations shown in the illustrations. Avoid touching the seals for at least 24 hours to allow time for the seals to properly adhere to the appliance and physical kit surfaces. Figure 14 – M-200: Seal locations on Top and Right Side Figure 15 – M-200: Seal Locations on Left Side and Rear M-300 Tamper Seal Installation (15 Seals)
  3. Replace the top cover with the FIPS top cover. a. Remove the VOID WARRANTY label and cover screws (replacement label included in the kit). © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 28
Page 29

M-300 appliance—Remove the Void Warranty label that covers the left top cover screw then use a Phillips-head screwdriver to remove both screws as indicated in the illustration. b. Simultaneously depress the two (2) release buttons on top of the cover and slide the cover toward the back of the appliance to remove it. c. Slide the physical kit top cover (does not have vents) on the appliance until the release buttons click. Reinsert and slide cover into position and secure with the two (2) screws. Figure 16 – M-300: Top Cover Replacement © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 29

Page 30
  1. On the left side of the M-300, firmly apply seven (7) tamper-evident seals as indicated in the illustration. Figure 17 – M-300: Side View Before Rail Installation Install the inner rack mount rail brackets as described in the “M-300 and M-700 Appliance Hardware Reference”. The front rack bracket that you replace in the next step is located on the front inner rails. Figure 18 – M-200: Inner Rack Mount Rail Brackets
  2. Attach the physical kit front cover brackets. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 30
Page 31

Replace the front rack-mount brackets (one bracket on each side) that are part of the inner-rack rails with the physical kit rack-mount brackets by removing and then reinstalling two screws on each bracket. The physical kit handles have standoffs that are used to secure the front cover. Figure 19

Page 32
  1. Attach the physical kit back cover to the back of the appliance. Slide the back cover onto the back of the appliance, insert two M4 x 0.7 x 8mm (one (1) screw on each side), and turn the screws clockwise to secure the cover.
  2. Apply a tamper-evident seal to each location shown in the following M-300 illustrations. Ensure you apply two (2) tamper-evident seals on the power supplies (see seals #14 and #15 on the rear illustration). Note: Before you apply the tamper-evident seals, ensure that the appliance and physical kit surfaces are clean and dry. Firmly press one (1) seal on to each of the locations shown in the illustrations. Avoid touching the seals for at least 24 hours to allow time for the seals to properly adhere to the appliance and physical kit surfaces. Figure 21 – M-300: Seal locations on Top and Right Side Figure 22 – M-300: Seal Locations on Left Side and Rear M-600 Tamper Seal Installation (21 Seals)
  3. Replace the top cover with the FIPS top cover. a. Remove the VOID WARRANTY label and cover screws (replacement label included in the kit). © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 32
Page 33

Remove the Void Warranty label that covers the left side cover screw then use a Phillips-head screwdriver to remove both screws as indicated in the illustration. b. Simultaneously depress the two (2) release buttons on top of the cover and slide the cover toward the back of the appliance to remove it. c. Slide the physical kit top cover (does not have vents) on the appliance until the release buttons click. Replace the two screws that you removed from the old cover Figure 23 – M-600: Top Cover Replacement 2. Attach the physical front cover brackets. Remove the front pull handles by removing two (2) screws from each handle (one (1) handle on each side), insert the M-600 physical kit front-cover brackets under each handle, and then replace the handles and secure them using the screws that you removed. The physical kit handles have standoffs that are used to secure the front cover. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 33

Page 34

Figure 24 – M-600: Front Cover Bracket

  1. Attach the physical kit front cover to the front of the appliance. Slide the M-600 physical kit front cover over the physical kit pull handle brackets and secure the cover by turning the thumb screws clockwise (one thumb screw on each side). Figure 25 – M-600: Physical Kit Front Cover
  2. Install a tamper-evident seal on the back of the appliance. This is seal #13 in the M-600 Figure
  3. You need to install this seal before you install the M-600 physical kit back cover.
  4. Attach the physical kit back cover to the back of the appliance. a. Slide the back cover onto the back of the appliance and turn the two (2) thumb screws clockwise until tight (one (1) screw on each side) to secure the cover.
  5. Apply a tamper-evident seal to each location shown in the following M-600 illustrations below. Also install the overlay stickers to cover vent openings (two (2) stickers on each side). You then install © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 34
Page 35

tamper-evident seals over the overlay stickers. Apply two (2) tamper-evident seals on the back side of the right rack handle (see seals #18 and #19 on the left side in Figure 54). Apply two (2) tamper-evident seals on the power supplies (see seals #11 and #12 with rear inset of Figure 53). Note: Before you apply the tamper-evident seals, ensure that the appliance and physical kit surfaces are clean and dry. Firmly press one (1) seal on to each of the locations shown in the illustrations. Avoid touching the seals for at least 24 hours to allow time for the seals to properly adhere to the appliance and physical kit surfaces. M-600 Seal Placement (21 Seals) Figure 26 – M-600: Tamper Seal Locations (Top and Rear) © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 35

Page 36

Figure 27

Page 37

Figure 29 – M-700: Top Cover Replacement

  1. Attach the physical kit front cover brackets. Remove the front pull handles by removing two (2) screws from each handle (one (1) handle on each side), insert the M-700 physical kit front-cover brackets under each handle, and then replace the handles and secure them using the screws that you removed. The physical kit handles have standoffs that are used to secure the front cover. Figure 30 – M-700: Front Cover Bracket
  2. Attach the physical kit front cover to the front of the appliance. Slide the M-700 physical front cover over the physical kit pull handle brackets and secure the cover by turning the thumb screws clockwise (one thumb screw on each side). © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 37
Page 38

Figure 31 – M-700: Physical Kit Front Cover

  1. Install a tamper-evident seal on the back of the appliance. This is seal #13 in the M-700 Figure
  2. You need to install this seal before you install the M-700 physical kit back cover.
  3. Attach the physical kit back cover to the back of the appliance. a. Slide the back cover onto the back of the appliance and turn the two (2) thumb screws clockwise until tight (one (1) screw on each side) to secure the cover.
  4. Apply a tamper-evident seal to each location shown in the following M-700 illustrations below. Also install the overlay stickers to cover vent openings (two (2) stickers on each side). You then install tamper-evident seals over the overlay stickers. Apply two (2) tamper-evident seals on the back side of the right rack handle (see seals #18 and #19 on the left side in Figure 54). Apply two (2) tamper-evident seals on the power supplies (see seals #11 and #12 with rear inset of Figure 53). Note: Before you apply the tamper-evident seals, ensure that the appliance and physical kit surfaces are clean and dry. Firmly press one (1) seal on to each of the locations shown in the illustrations. Avoid touching the seals for at least 24 hours to allow time for the seals to properly adhere to the appliance and physical kit surfaces. M-700 Seal Placement (21 Seals) Figure 32 – M-700: Tamper Seal Locations (Top and Rear) © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 38
Page 39

Figure 33

Page 40
Key/SSP/Name /TypeStrengthSecurity Functionand Cert. NumberGenerati onImport/Exp ortEstablishm entStorageZeroization1Use&RelatedKeys
CACertificates112bitsminimumRSASigVer(FIPS 186-4) ECDSASigVer (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4TLSorSSH SessionKey EncryptedN/AHDD/RAM– plaintextHDD– Zeroize Service RAM-Zeroize atsession terminationECDSA/RSAPublickey- UsedtotrustarootCA intermediateCAand leaf/endentity certificates (RSA2048,3072,and 4096bits) (ECDSAP-256,P-384, andP-521)
RSAPublicKeys112bitsminimumRSASigVer (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4TLSorSSH SessionKey Encryptedor Plaintext TLShandshakeN/AHDD/RAM– plaintextZeroize ServiceRSApublickeys managedascertificates fortheverificationof signatures, establishmentofTLS, operatorauthentication andpeer authentication. (RSA2048,3072,or 4096-bit)
RSAPrivateKeys112bitsminimumRSASigGen (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4TLSorSSH SessionKey EncryptedN/AHDD/RAM– plaintextHDD–Zeroize Service RAM-Zeroizeat session terminationRSAPrivatekeysfor generationof signatures, authenticationorkey establishment. (RSA2048,3072,or 4096-bit)
ECDSAPublic Keys128bitsminimumECDSASigVer (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4TLSorSSH SessionKey Encryptedor Plaintext TLShandshakeN/AHDD/RAM– plaintextZeroizeServiceECDSApublickeys managedascertificates fortheverificationof signatures, establishmentofTLS, operatorauthentication andpeer authentication. (ECDSAP-256,P-384, orP-521)
ECDSAPrivate Keys128bitsminimumECDSASigGen (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4TLSorSSH SessionKey EncryptedN/AHDD/RAM– plaintextHDD–Zeroize Service RAM-Zeroizeat session terminationECDSAPrivatekeyfor generationofsignatures andauthentication (P-256,P-384,or P-521)
TLSDHE/ECDHE Private Components112bitsminimumKAS-ECC-SSC KAS-FFC-SSC Cert.#A2906DRBG,SP 800-56ARev. 3N/AN/ARAM-plaintextZeroizeatsession terminationKAS-FFCorKAS-ECC Ephemeralvaluesused inkeyagreement (KAS-FFCMODP-2048, KAS-ECCP-256,P-384, P-521)
TLSDHE/ECDHE Public Components112bitsminimumKAS-ECC-SSC KAS-FFC-SSC Cert.#A2906DRBG,SP 800-56ARev. 3Plaintext-TLS handshakeN/AN/AZeroizeatsession terminationKAS-FFCorKAS-ECC Ephemeralvaluesused inkeyagreement (KAS-FFCMODP-2048, KAS-ECCP-256,P-384, P-521)
TLSPre-Master SecretN/AKDFTLS Cert.#A2906KASSP 800-56ARev. 3N/AN/ARAM–plaintextZeroizeatsession terminationSecretvalueusedto derivetheTLSMaster Secretalongwithclient andserverrandom nonces
Table, extracted as text (did not parse into structured rows)
9. Sensitive Security Parameters The following table details all the sensitive security parameters utilized by the module. Table 10 - SSPs Used to trust a root CA RSA SigVer (FIPS                                                                   HDD – intermediate CA and TLS or SSH                                                            leaf /end entity CA Certificates    112 bits minimum                                  Session Key      N/A                                                  certificates at session
4096 bits)
Table, extracted as text (did not parse into structured rows)
managed as certificates for the verification of RSA SigVer                       Session Key and peer RSA Private keys for HDD – Zeroize        generation of RSA SigGen                       TLS or SSH                                       Service              signatures, managed as certificates for the verification of and peer ECDSA SigGen                     TLS or SSH                                       Service              generation of signatures Ephemeral values used Zeroize at session   in key agreement Private            112 bits minimum KAS-FFC-SSC        800-56A Rev. N/A               N/A           RAM - plaintext Ephemeral values used Public             112 bits minimum KAS-FFC-SSC        800-56A Rev.                   N/A           N/A Secret value used to TLS Pre-Master                      KDF TLS                                                                           Zeroize at session N/A                                 800-56A Rev. N/A               N/A           RAM – plaintext                        Secret along with client

3 and server random

© 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 40

Page 41
TLSMaster SecretN/AKDFTLS Cert.#A2906KDFTLSN/AN/ARAM–plaintextZeroizeatsession terminationSecretvalueusedto derivetheTLSsession keys
TLSEncryption Keys128bitsminimumAES-CBCor AES-GCM Cert.#A2906KDFTLSN/ATLS,KASSP 800-56ARev.3RAM-plaintextZeroizeatsession terminationAES(128or256bit) keysusedinTLS connections(GCM; CBC)
TLSHMACKeys256bitsminimumHMAC-SHA2-256 HMAC-SHA2-384 Cert.#A2906KDFTLSN/ATLS,KASSP 800-56ARev.3RAM-plaintextZeroizeatsession terminationHMACkeysusedinTLS connections(SHA-256, SHA-384) (256,384bits)
SSH DHE/ECDHE Private Components112bitsminimumKAS-ECC-SSC KAS-FFC-SSC Cert.#A2906DRBG,SP 800-56ARev. 3N/AN/ARAM-plaintextZeroizeatsession terminationKAS-FFCorKAS-ECC publiccomponent (KAS-FFCMODP-2048, KAS-ECCP-256, KAS-ECCP-384, KAS-ECCP-521)
SSH DHE/ECDHE Public Components112bitsminimumKAS-ECC-SSC KAS-FFC-SSC Cert.#A2906DRBG,SP 800-56ARev. 3PlaintextSSH handshakeN/ARAM-plaintextZeroizeatsession terminationKAS-FFCorKAS-ECC publiccomponent (KAS-FFCMODP-2048, KAS-ECCP-256, KAS-ECCP-384, KAS-ECCP-521)
SSHHostPublic Key112bitsminimumRSASigVer (FIPS186-4) ECDSASigVer (FIPS186-4) Cert.#A2906DRBG,FIPS 186-4N/AN/AHDD/RAM– plaintextZeroizeServiceSSHHostPublicKey (RSA2048,RSA3072, RSA4096,ECDSA P-256,P-384,orP-521)
SSHClientPublic Key112bitsminimumRSASigVer (FIPS186-4) Cert.#A2906N/AEncryptedvia SSHorTLSN/AHDD/RAM– plaintextZeroizeServicePublicRSAkeyusedto authenticateclient. (RSA2048,3072,and 4096bits)
SSHSession EncryptionKeys128bitsminimumAES-CBC, AES-CTR,or AES-GCM Cert.#A2906KDFSSHN/ASSH,KASSP 800-56ARev.3RAM-plaintextZeroizeatsession terminationUsedinallSSH connectionstothe securitymodule’s commandlineinterface. (128,192,or256bits: CBCorCTR) (128or256bits:GCM)
SSHSession Authentication Keys160bitsminimumHMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 Cert.#A2906KDFSSHN/ASSH,KASSP 800-56ARev.3RAM-plaintextZeroizeatsession terminationAuthenticationkeys usedinallSSH connectionstothe securitymodule’s commandlineinterface (HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-512) (160,256,512bits)
Firmware integrity verificationkey128bitsHMAC-SHA2-256, ECDSASigVer (FIPS186-4) Cert.#A2906N/AN/AN/AHDD- plaintextN/AUsedtocheckthe integrityof crypto-relatedcode. (HMAC-SHA-256and ECDSAP-256)(Note: Thisisnotconsideredan SSP)
PublicKeyfor FirmwareLoad Test112bitsRSASigVer (FIPS186-4) Cert.#A2906N/AN/AN/AHDD- plaintextN/AUsedtoauthenticate firmwareandcontentto beinstalledonthe firewall(RSA2048with SHA-256)
CO,User PasswordN/ASHA2-256 Cert.#A2906ExternalEncryptedvia SSHorTLSN/AHDD-apassword hash(SHA2-256)Zeroize ServiceAuthenticationstring withaminimumlength ofeight(8)characters.
ProtocolSecretsN/AN/AN/AEncryptedvia SSHorTLSN/AHDD/RAM– plaintextZeroize ServiceSecretsusedbyRADIUS (8charactersminimum)
Table, extracted as text (did not parse into structured rows)
Secret value used to TLS Master                             KDF TLS                                                                         Zeroize at session N/A                               KDF TLS      N/A             N/A              RAM – plaintext                         derive the TLS session TLS Encryption                                                                     TLS, KAS SP                         Zeroize at session   keys used in TLS
112 bits minimum KAS-FFC-SSC      800-56A Rev. N/A             N/A              RAM - plaintext
112 bits minimum KAS-FFC-SSC      800-56A Rev.                 N/A              RAM - plaintext
112 bits minimum                               N/A             N/A                                 Zeroize Service
Public RSA key used to RSA SigVer SSH Client Public                                                  Encrypted via                    HDD/RAM –                               authenticate client.
112 bits minimum (FIPS 186-4)     N/A                          N/A                                 Zeroize Service
4096 bits)

Used in all SSH connections to the security module’s

Table, extracted as text (did not parse into structured rows)
128 bits minimum                  KDF SSH      N/A                              RAM - plaintext                         command line interface.
used in all SSH connections to the SSH Session                                                                                                                                 security module’s Authentication      160 bits minimum                 KDF SSH       N/A                              RAM - plaintext                         command line interface Used to check the integrity of Firmware                                                                                                                                    crypto-related code. This is not considered an Used to authenticate Public Key for                         RSA SigVer                                                                                           firmware and content to Firmware Load       112 bits           (FIPS 186-4)   N/A          N/A             N/A                                  N/A                 be installed on the Authentication string N/A                               External                     N/A                                                      with a minimum length of eight (8) characters. Encrypted via                     HDD/RAM –          Zeroize             Secrets used by RADIUS Protocol Secrets    N/A                N/A            N/A                          N/A © 2024 Palo Alto Networks, Inc.                                                                                 Panorama HW 10.2 Security Policy 41
Page 42
EntropyInput String256bitsCKG(vendor affirmed),Counter DRBG Cert.#A2906Entropyas per SP800-90BN/AN/ARAM-plaintextPowercycleEntropyinputstring comingfromthe entropysource Inputlength=384bits
DRBGSeed256bitsCKG(vendor affirmed),Counter DRBG Cert.#A2906Entropyas per SP800-90BN/AN/ARAM-PlaintextPowercycleDRBGseedcomingfrom theentropysource Seedlength=384bits
DRBGKey256bitsCKG(vendor affirmed),Counter DRBG Cert.#A2906Entropyas per SP800-90BN/AN/ARAM-plaintextPowercycleAES256CTRDRBG stateKeyusedinthe generationofarandom values
DRBGV128bitsCKG(vendor affirmed),Counter DRBG Cert.#A2906Entropyas per SP800-90BN/AN/ARAM-plaintextPowercycleAES256CTRDRBG stateVusedinthe generationofarandom values
SNMPv3 Authentication SecretN/AKDFSNMP Cert.#A2906N/AEncryptedvia TLS/SSHN/AHDD/RAM– plaintextZeroize ServiceUsedtosupportSNMPv3 services (Minimum8characters)
SNMPv3Privacy SecretN/AKDFSNMP Cert.#A2906N/AEncryptedvia TLS/SSHN/AHDD/RAM– plaintextZeroize ServiceUsedtosupportSNMPv3 services (Minimum8characters)
SNMPv3 Authentication Key160bitsminimumHMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 Cert.#A2906KDFSNMPN/AN/AHDD/RAM- PlaintextZeroize ServiceHMAC–SHA-1/224/256 /384/512 Authenticationprotocol key(160bits)
SNMPv3Session Key128bitsminimumAES-CFB128 Cert.#A2906KDFSNMPN/AN/AHDD/RAM- PlaintextZeroize ServicePrivacyprotocol encryptionkey (AES-CFB128)
EntropySourceMinimumnumberof bitsofentropyDetails
PaloAltoNetworksDRNG EntropySource256bitsESVCert.#E64,#E65,#E66 Entropysourceprovidesfullentropy,whichisprovidedinthe384 bitseed.
Table, extracted as text (did not parse into structured rows)
Entropy input string Entropy as                                                               coming from the Entropy Input                       DRBG
256 bits                              per          N/A             N/A       RAM - plaintext   Power cycle     entropy source
SP 800-90B Input length = 384 bits affirmed), Counter                                                                         DRBG seed coming from Entropy as DRBG                                                                                       the entropy source DRBG Seed         256 bits                              per          N/A             N/A       RAM - Plaintext   Power cycle SP 800-90B Cert. #A2906                                                                               Seed length = 384 bits Entropy as DRBG                                                                                        state Key used in the generation of a random SP 800-90B Entropy as DRBG                                                                                        state V used in the DRBG V           128 bits                              per          N/A             N/A       RAM - plaintext   Power cycle generation of a random SP 800-90B Used to support SNMPv3 Authentication                      KDF SNMP                        Encrypted via               HDD/RAM –        Zeroize (Minimum 8 characters) Used to support SNMPv3 SNMPv3 Privacy                      KDF SNMP                        Encrypted via               HDD/RAM –        Zeroize (Minimum 8 characters) Authentication   160 bits minimum               KDF SNMP            N/A             N/A Privacy protocol
128 bits minimum                    KDF SNMP       N/A             N/A                                         encryption key

(AES-CFB 128) Note: SSPs are implicitly zeroized when power is lost, or explicitly zeroized by the zeroize service. In the case of implicit zeroization, the SSPs are implicitly overwritten with random values due to their ephemeral memory being reset upon power loss. For the zeroization service and zeroization at session termination, the SSP's memory location is overwritten with random values. Table 11 – Non-Deterministic Random Number Generation Specification Entropy Source Minimum number of Details bits of entropy Palo Alto Networks DRNG 256 bits Entropy Source Entropy source provides full entropy, which is provided in the 384 bit seed. 10. Self-Tests The cryptographic module performs the following tests below. The operator can command the module to perform the power-up self-test by cycling power of the module; these tests do not require any operator action. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 42

Page 43

Pre-operational Self-Tests Pre-operational Firmware Integrity Test

Page 44
CauseofErrorErrorStateIndicator
ConditionalCryptographicAlgorithmSelf-TestorFirmware IntegrityTestFailureFIPS-CCmodefailure. <Algorithmtest>failed.
ConditionalPairwiseConsistencyorCriticalFunctionsTest FailureSystemlogprintsanerrormessage.
ConditionalFirmwareLoadTestFailureSystemprintsInvalidimagemessage.

Conditional Critical Functions Tests ● SP 800-56A Rev. 3 Assurance Tests (Based on Sections 5.5.2, 5.6.2, and 5.6.3) Error Handling In the event of a conditional test failure, the module will output a description of the error. These are summarized below. Table 12 - Errors and Indicators Cause of Error Error State Indicator Conditional Cryptographic Algorithm Self-Test or Firmware FIPS-CC mode failure. <Algorithm test> failed. Integrity Test Failure Conditional Pairwise Consistency or Critical Functions Test System log prints an error message. Conditional Firmware Load Test Failure System prints Invalid image message.

  1. Life-cycle Assurance The vendor provided life-cycle assurance documentation that describes configuration management, design, finite state model, development, testing, delivery + operation, end of life procedures, and guidance. For details regarding the secure installation, initialization, startup, and operation of the module, see section “Modes of Operation”. Palo Alto Network provides an Administrator Guide for additional information noted in the “References” section of this Security Policy. Module Enforced Security Rules The module design corresponds to the module security rules. This section documents the security rules enforced by the cryptographic module to implement the security requirements of this FIPS 140-3 Level 2 module.
  2. The cryptographic module shall provide distinct operator roles. When the module has not been placed in a valid role, the operator shall not have access to any cryptographic services.
  3. The cryptographic module shall provide identity-based authentication.
  4. The cryptographic module shall clear previous authentications on power cycle.
  5. The module shall support the generation of key material with the approved DRBG. The entropy provided must be greater than or equal to the strength of the key being generated.
  6. Data output shall be inhibited during power-up self-tests and error states.
  7. Processes performing key generation and zeroization processes shall be logically isolated from the logical data output paths.
  8. The module does not output intermediate key generation values.
  9. Status information output from the module shall not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  10. There are no restrictions on which keys or CSPs are zeroized by the zeroization service.
  11. The module maintains separation between concurrent operators.
  12. The module does not support a maintenance interface or role.
  13. The module does not have any external input/output devices used for entry/output of data.
  14. The module does not enter or output plaintext CSPs. © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 44
Page 45

Vendor imposed security rules In FIPS-CC mode, the following rules shall apply:

  1. When FIPS-CC mode is enabled, the operator shall not install plugins. a. Checked via CLI using “show plugins installed”
  2. When FIPS-CC mode is enabled, the operator shall not use TACACS+. RADIUS may be used but must be protected by TLS protocol. a. Checked via CLI using “show deviceconfig” command Key to Entity The cryptographic module associates all keys (secret, private, or public) stored within, entered into or output from the module with authenticated operators of the module. Keys stored within the module are only made available to authenticated operators via TLS or SSH. Keys are only input or output from the module by the authenticated operator via a SSH or TLS protected communication. Any attempt to intervene in the key to entity relationship would require defeating the module TLS or SSH encryption and authentication/integrity mechanism.
  3. Mitigation of Other Attacks The module is not designed to mitigate any specific attacks outside the scope of FIPS 140-3. These requirements are not applicable.
  4. References [FIPS 140-3] FIPS Publication 140-3 Security Requirements for Cryptographic Modules [AGD] Panorama Administrator’s Guide Version 10.2
  5. Definitions and Acronyms AES – Advanced Encryption Standard CA – Certificate Authority CLI – Command Line Interface CO – Crypto-Officer CSP – Critical Security Parameter CVL – Component Validation List DB9 – D-sub series, E size, 9 pins DES – Data Encryption Standard DH – Diffie-Hellman DRBG – Deterministic Random Bit Generator EDC – Error Detection Code ECDH – Elliptical Curve Diffie-Hellman ECDSA – Elliptical Curve Digital Signature Algorithm FIPS – Federal Information Processing Standard © 2024 Palo Alto Networks, Inc. Panorama HW 10.2 Security Policy 45
Page 46

HMAC