Derived Review-Risk Graph (review prompts, not findings)
flowchart LR
%% Deterministic review-risk graph for Panorama Virtual Appliance 10.2
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>self-test</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;Underlying clues
flowchart LR
%% Deterministic clue tier for Panorama Virtual Appliance 10.2
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>self-test</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Security Policy, page by page
Panorama Virtual Appliance 10.2 Version: 1.2 Revision Date: August 28, 2024 Palo Alto Networks, Inc. www.paloaltonetworks.com © 2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
| ISO/IEC24759Section6. | FIPS140-3SectionTitle | SecurityLevel |
|---|
| 1 | General | 1 |
| 2 | CryptographicModuleSpecification | 1 |
| 3 | CryptographicModuleInterfaces | 1 |
| 4 | Roles,Services,andAuthentication | 3 |
| 5 | Software/FirmwareSecurity | 1 |
| 6 | OperationalEnvironment | 1 |
| 7 | PhysicalSecurity | N/A |
| 8 | Non-InvasiveSecurity | N/A |
| 9 | SecurityParameterManagement | 1 |
| 10 | Self-Tests | 1 |
| 11 | Life-CycleAssurance | 3 |
| 12 | MitigationofOtherAttacks | N/A |
| OverallLevel | | 1 |
| OperatingSystem | HardwarePlatform | Processor | PAA/Acceleration |
|---|
| VMwareESXiv7.0 | DellPowerEdgeR740 | IntelGold6248 | N/A |
| KVMonUbuntu20.04 | DellPowerEdgeR740 | IntelGold6248 | N/A |
| Hyper-V2019onMicrosoft Hyper-VServer2019 | DellPowerEdgeR740 | IntelGold6248 | N/A |
The Panorama Virtual Appliance 10.2 from Palo Alto Networks Inc., hereafter referred to as “Panorama VM” or the “cryptographic module” are multi-chip standalone cryptographic modules designed to fulfill FIPS 140-3 level 1 requirements. The Panorama VM provides a centralized monitoring and management of multiple Palo Alto Networks next-generation (NG) firewalls and Wildfire appliances. For purposes of this validation, the exact software version of the module tested was 10.2.3-h1. The cryptographic module meets the overall requirements applicable to Level 1 security of FIPS 140-3. Table 1 - Security Levels ISO/IEC 24759 Section 6. FIPS 140-3 Section Title Security Level
Table, extracted as text (did not parse into structured rows)
2 Cryptographic Module Specification 1
3 Cryptographic Module Interfaces 1
4 Roles, Services, and Authentication 3
5 Software/Firmware Security 1
6 Operational Environment 1
7 Physical Security N/A
8 Non-Invasive Security N/A
9 Security Parameter Management 1
11 Life-Cycle Assurance 3
12 Mitigation of Other Attacks N/A
Overall Level 1 2. Cryptographic Module Specification The tested operational environments are highlighted in Table 2. Table 2 – Tested Operational Environments Operating System Hardware Platform Processor PAA/Acceleration VMware ESXi v7.0 Dell PowerEdge R740 Intel Gold 6248 N/A KVM on Ubuntu 20.04 Dell PowerEdge R740 Intel Gold 6248 N/A Hyper-V 2019 on Microsoft Dell PowerEdge R740 Intel Gold 6248 N/A Hyper-V Server 2019 © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 3
| OperatingSystem | HardwarePlatform |
|---|
| AmazonWebServices(AWS) MicrosoftAzure GoogleCloudPlatform(GCP) | x86Architecture (Note:Specificprocessor/hardwareisdependenton Instance/MachineTypeselectedforoperationsystem) |
Table 3
- Vendor Affirmed Operational Environments Operating System Hardware Platform Amazon Web Services (AWS) x86 Architecture Microsoft Azure (Note: Specific processor/hardware is dependent on Google Cloud Platform (GCP) Instance/Machine Type selected for operation system) Operator Porting Rules The CMVP allows user porting of a validated software module to an operational environment which was not included as part of the validation testing. An operator may install and run this module on any general purpose computer (GPC) or platform using the specified hypervisor and operating system on the validation certificate or other compatible operating and/or hypervisor system and affirm the module's continued FIPS 140-3 validation compliance. The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported and executed in an operational environment not listed on the validation certificate. Approved Mode of Operation The following procedure will initialize the modules into the Approved mode of operation:
- During initial boot up, break the boot sequence via the console port connection (by pressing the maint button when instructed to do so) to access the main menu.
- Select “Continue.”
- Select the “Set FIPS-CC Mode” option to initialize the Approved mode.
- Select “Enable FIPS-CC Mode”.
- When prompted, select “Reboot” and the module will re-initialize and continue into the Approved mode of operation (FIPS-CC mode).
- The module will reboot.
- In “FIPS-CC” mode, the console port is available only as a status output port.
- Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module
- Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten The module will automatically indicate the Approved mode of operation in the following manner:
- Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session.
- Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port.
- The module will display “FIPS-CC” at all times in the status bar at the bottom of the web interface.
- The module will display “fips-cc” when “show system info” is entered via the CLI Should one or more self-tests fail in Section 10, the Approved mode of operation will not be achieved. Feedback will consist of:
- The module will output “FIPS-CC failure”
- The module will reboot and enter a state in which the reason for the reboot can be determined.
- To determine which self-test caused the system to reboot into the error state, connect the console cable and follow the on-screen instructions to view the self-test output. Note: Disabling “FIPS-CC” mode causes a complete factory reset, which is described in the Zeroization section below. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 4
Non-Compliant State Failure to follow the directions in the Approved Mode of Operation above and Section 11 will result in the module operating in a non-compliant state. Selecting Panorama, Management-Only, and Log Collector System Modes The Panorama VM supports multiple configurations that provide varying services. The Cryptographic Officer can initialize the module into different System Mode. The module supports the following System Modes:
- Panorama
- Management-Only
- Log Collector The default and primary mode of operation is Panorama mode. An additional mode, Log Collector mode, focuses primarily on log gathering instead of management. The final mode supported by the module is Management-Only, which focuses primarily on management functions without logging capabilities. To convert the module from the default mode, Panorama mode, to Log Collector or Management-Only mode, follow the steps below: Convert the Panorama VM from Panorama mode to Log Collector or Management-Only mode:
- Log into the CLI via SSH, CO is authenticated with username/password
- Enter “request system system-mode logger” or “request system system-mode management-only”
- Enter “Y” to confirm the change to the selected mode.
- The system will reboot and perform the required power on self-tests. Convert the Panorama VM from Log Collector or Management-Only mode to Panorama mode:
- Log into the CLI via SSH, CO is authenticated with username/password
- Enter “request system system-mode panorama”
- Enter “Y” to confirm the change to the selected mode.
- The system will reboot and perform the required power on self-tests Note: Changing the System Mode does not change FIPS-CC Mode. Zeroization The following procedure will zeroize the module:
- Access the module’s CLI via SSH, and command the module to enter maintenance mode (“debug system maintenance-mode”); the module will reboot
- Note: Establish a serial connection to the console port
- After reboot, select “Continue.”
- Select “Factory Reset”
- The module will perform a zeroization, and provide the following message once complete: o “Factory Reset Status: Success” Note: Following the completion of this procedure, the module will be placed back into an uninitialized state. Uninitialized State If the module does not successfully transition into the Approved mode of operation, or zeroization is performed, the module will be in an uninitialized state. It is required to initialize the module in order to perform cryptographic functions. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 5
| CAVP Cert | Algorithm andStandard | Mode/Method | Description/KeySize(s)/Key Strength(s) | Use/Function |
|---|
| A1791 | Conditioning Component AES-CBC-MACSP 800-90B | AES-CBC-MAC | 128bits | VettedconditioningcomponentforESV Cert.#E69 |
| A2907 | AES-CBC[SP 800-38A] | CBC | 128,192and256bits | Encryption Decryption |
| A2907 | AES-CFB128[SP 800-38A] | CFB128 | 128bits | Encryption Decryption |
| A2907 | AES-CTR[SP 800-38A] | CTR | 128,192and256bits | Encryption Decryption |
| A2907 | AES-GCM [SP800-38D] | GCM** | 128and256bits | Encryption Decryption |
| A2907 | CounterDRBG [SP800-90Arev1] | CounterDRBG | AES256bitswithDerivationFunctionEnabled | RandomBitGenerator |
| A2907 | ECDSAKeyGen (FIPS186-4) | ECDSAKeyGen (FIPS186-4) | P-256,P-384,P-521 | KeyGeneration |
| A2907 | ECDSAKeyVer (FIPS186-4) | ECDSAKeyVer (FIPS186-4) | P-256,P-384,P-521 | PublicKeyValidation |
| A2907 | ECDSASigGen (FIPS186-4) | ECDSASigGen (FIPS186-4) | P-256,P-384,P-521withSHA2-224,SHA2-256, SHA2-384,andSHA2-512 | SignatureGeneration |
| A2907 | ECDSASigVer (FIPS186-4) | ECDSASigVer (FIPS186-4) | P-256,P-384,P-521withSHA-1,SHA2-224, SHA2-256,SHA2-384,andSHA2-512 | SignatureVerification |
| A2907 | HMAC-SHA-1 [FIPS198-1] | HMAC | HMAC-SHA-1withλ=160 | Authenticationforprotocols |
| A2907 | HMAC-SHA2-224 [FIPS198-1] | HMAC | HMAC-SHA2-224withλ=224 | Authenticationforprotocols |
| A2907 | HMAC-SHA2-256 [FIPS198-1] | HMAC | HMAC-SHA2-256withλ=256 | Authenticationforprotocols |
| A2907 | HMAC-SHA2-384 [FIPS198-1] | HMAC | HMAC-SHA2-384withλ=384 | Authenticationforprotocols |
| A2907 | HMAC-SHA2-512 [FIPS198-1] | HMAC | HMAC-SHA2-512withλ=512 | Authenticationforprotocols |
| A2907 | KAS-ECC-SSC Sp800-56Ar3 | KAS | EphemeralUnifiedModel:P-256/P-384/P-521 | KeyExchange |
| A2907 | KAS-FFC-SSCSP 800-56Ar3 | KAS | dhEphem:MODP-2048 | KeyExchange |
| A2907 | KDFSNMP[SP 800-135rev1] (CVL) | SNMPv3KDF | EngineID: 80001F88043030303030 343935323630 | SNMPv3 |
Approved and Allowed Algorithms The cryptographic modules support the following Approved algorithms. Only the algorithms, modes, and key sizes specified in this table are used by the module. The CAVP certificate may contain more tested options than listed in this table. Table 4 – Approved Algorithms Cert and Standard Strength(s) Component Vetted conditioning component for ESV
128 and 256 bits
Table, extracted as text (did not parse into structured rows)
Counter DRBG A2907 Counter DRBG AES 256 bits with Derivation Function Enabled Random Bit Generator ECDSA KeyGen ECDSA KeyGen Key Generation (FIPS 186-4) (FIPS 186-4) ECDSA KeyVer ECDSA KeyVer Public Key Validation (FIPS 186-4) (FIPS 186-4) ECDSA SigGen ECDSA SigGen P-256, P-384, P-521 with SHA2-224, SHA2-256, Signature Generation (FIPS 186-4) (FIPS 186-4) SHA2-384, and SHA2-512 A2907 Signature Verification (FIPS 186-4) (FIPS 186-4) SHA2-256, SHA2-384, and SHA2-512 HMAC HMAC-SHA-1 with λ=160 Authentication for protocols [FIPS 198-1] HMAC Authentication for protocols [FIPS 198-1] HMAC HMAC-SHA2-256 with λ=256 Authentication for protocols [FIPS 198-1] HMAC HMAC-SHA2-384 with λ=384 Authentication for protocols [FIPS 198-1] HMAC HMAC-SHA2-512 with λ=512 Authentication for protocols [FIPS 198-1] KDF SNMP [SP Engine ID: © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 6
| A2907 | KDFSSH[SP 800-135rev1] (CVL) | SSHv2KDF | SHA-1,SHA2-256, SHA2-512 | SSH |
|---|
| A2907 | KDFTLS[SP 800-135rev1] (CVL) | TLS1.2KDF | TLSv1.2HashAlgorithm:SHA2-256,SHA2-384 | TLS |
| A2907 | RSA KeyGen (FIPS186-4) | RSA KeyGen(FIPS 186-4) | 2048,3072,and4096bits | KeyPairGeneration |
| A2907 | RSA SigGen (FIPS186-4) | RSA SigGen(FIPS 186-4) | (ANSIX9.31,RSASSA-PKCS1_v1-5, RSASSA-PSS):2048,3072,and4096-bitwith hashesSHA2-256/384/512 | SignatureGeneration |
| A2907 | RSA SigVer(FIPS 186-4) | RSA SigVer(FIPS 186-4) | (ANSIX9.31,RSASSA-PKCS1_v1-5, RSASSA-PSS):2048,3072,4096-bit(perIGC.F) withhashesSHA-1and SHA2-224+++/256/384/512(Signature Verification) +++ThisHashalgorithmisnotsupportedfor ANSIX9.31 | SignatureVerification |
| A2907 | SHA-1[FIPS 180-4] | SHA | SHA-1 | DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC) |
| A2907 | SHA2-224[FIPS 180-4] | SHA2 | SHA-224 | DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC) |
| A2907 | SHA2-256[FIPS 180-4] | SHA2 | SHA-256 | DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC) |
| A2907 | SHA2-384[FIPS 180-4] | SHA2 | SHA-384 | DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC) |
| A2907 | SHA2-512[FIPS 180-4] | SHA2 | SHA-512 | DigitalSignature Generation/Verification Non-DigitalSignatureApplications (e.g.componentofHMAC) |
| A2907 | SafePrimesKey Generation[RFC 3526] | SafePrimesKey Generation | MODP-2048 | SafePrimesKeyGeneration |
| A2907 | SafePrimesKey Verification[RFC 3526] | SafePrimesKey Verification | MODP-2048 | SafePrimesKeyVerification |
| AESCert. #A2907 andHMAC Cert #A2907 | KTS[SP 800-38F] | SP800-38A,FIPS 198-1,andSP 800-38F.KTS(key wrappingand unwrapping)perIG D.G. | 128,192,and256-bitkeysproviding128,192,or 256bitsofencryptionstrength | KeyWrapping |
| AES-GCM Cert. #A2907 | KTS[SP 800-38F] | SP800-38DandSP 800-38F.KTS(key wrappingand | 128and256-bitkeysproviding128or256bits ofencryptionstrength | KeyWrapping |
TLS1.2 KDF with hashes SHA-1 and +++ This Hash algorithm is not supported for ANSI X9.31 Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Digital Signature Non-Digital Signature Applications (e.g. component of HMAC) Safe Primes Key Safe Primes Key Safe Primes Key Safe Primes Key and HMAC Key Wrapping 800-38F] wrapping and 256 bits of encryption strength unwrapping) per IG D.G. 800-38F] of encryption strength #A2907 wrapping and © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 7
| | unwrapping)perIG D.G. | | |
|---|
| ESVCert. #E69 | SP800-90B | ESV | PaloAltoNetworksDRNGEntropySource | Entropy |
| KAS-ECC-S SCCert. #A2907, KDFSSH Cert. #A2907 | KAS[SP 800-56Arev3] | SP800-56Arev3. KAS-ECCperIGD.F Scenario2path(2). | P-256,P-384,andP-521curvesproviding128, 192,or256bitsofencryptionstrength | KeyExchangewithprotocolKDF |
| KAS-ECC-S SCCert. #A2907, KDF TLSCert. #A2907 | KAS[SP 800-56Arev3] | SP800-56Arev3. KAS-ECCperIGD.F Scenario2path(2). | P-256,P-384,andP-521curvesproviding128, 192,or256bitsofencryptionstrength | KeyExchangewithprotocolKDF |
| KAS-FFC-S SCCert. #A2907, KDFSSH Cert. #A2907 | KAS[SP 800-56Arev3] | SP800-56Arev3. KAS-FFCperIGD.F Scenario2path(2). | 2048-bitkeyproviding112bitsofencryption strength | KeyExchangewithprotocolKDF |
| KAS-FFC-S SCCert. #A2907, KDFTLS Cert. #A2907 | KAS[SP 800-56Arev3] | SP800-56Arev3. KAS-FFCperIGD.F Scenario2path(2). | 2048-bitkeyproviding112bitsofencryption strength | KeyExchangewithprotocolKDF |
| Vendor Affirmed | CKG(SP 800-133rev2) | Section5.1,Section 5.2 | CryptographicKeyGeneration;SP800-133and IGD.H(asymmetricseeds). | KeyGeneration Note:Theseedsusedforasymmetric keypairgenerationareproducedusing theunmodified/directoutputofthe DRBG |
unwrapping) per IG D.G. SP 800-90B ESV Palo Alto Networks DRNG Entropy Source Entropy SC Cert. #A2907, KAS [SP P-256, P-384, and P-521 curves providing 128, KAS-ECC per IG D.F Key Exchange with protocol KDF KDF SSH 800-56Arev3] 192, or 256 bits of encryption strength Scenario 2 path (2). SC Cert. #A2907, KAS [SP P-256, P-384, and P-521 curves providing 128, KAS-ECC per IG D.F Key Exchange with protocol KDF Scenario 2 path (2). SC Cert. #A2907, KAS [SP 2048-bit key providing 112 bits of encryption KAS-FFC per IG D.F Key Exchange with protocol KDF Scenario 2 path (2). SC Cert. #A2907, KAS [SP 2048-bit key providing 112 bits of encryption KAS-FFC per IG D.F Key Exchange with protocol KDF Scenario 2 path (2). Key Generation Note: The seeds used for asymmetric Vendor CKG (SP Section 5.1, Section Cryptographic Key Generation; SP 800-133 and key pair generation are produced using Affirmed 800-133rev2) 5.2 IG D.H (asymmetric seeds). the unmodified/direct output of the ** The module is compliant to IG C.H: GCM is used in the context of TLS and SSH:
- For TLS, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with SP 800-52 and in accordance with Section 4 of RFC 5288 for TLS key establishment, and ensures when the nonce_explicit part of the IV exhausts all possible values for a given session key, that a new TLS handshake is initiated per sections 7.4.1.1 and 7.4.1.2 of RFC 5246. During operational testing, the module was tested against an independent version of TLS and found to behave correctly.
- From this RFC 5288, the GCM cipher suites in use are: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, and TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- For SSH, the module meets Scenario 1 of IG C.H. The module conforms to RFCs 4252, 4253, and 5647. The fixed field is 32 bits in length and is derived using the SSH KDF; this ensures the fixed field is unique for any given GCM session. The invocation field is 64 bits in length and is incremented for each invocation of GCM; this prevents the IV from repeating until the entire invocation field space of 264 is exhausted, which can take hundreds of years. (in FIPS-CC Mode, SSH rekey is automatically configured at 1 GB of data or 1 hour, whichever comes first) © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 8
In all the above cases, the nonce explicit is always generated deterministically. Also, AES GCM keys are zeroized when the module is power-cycled. For each new TLS or SSH session, a new AES GCM key is established. The module is compliant to IG C.F.: The module utilizes approved modulus sizes 2048, 3072, and 4096 bits for RSA signatures. This functionality has been CAVP tested as noted above. The minimum number of Miller Rabin tests for each modulus size is implemented according to Table C.2 of FIPS 186-4. For modulus size 4096 the module implements the largest number of Miller-Rabin tests shown in Table C.2. RSA SigVer is CAVP tested for all three supported modulus sizes as noted above. The module does not perform FIPS 186-2 SigVer. All supported modulus sizes are CAVP testable and tested as noted above. The module does not implement RSA key transport in the approved mode. The module does not have any algorithms that fall under: - Non-Approved Algorithms Allowed in the Approved Mode of Operation - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation Table 5 - Supported Protocols in the Approved Mode Supported Protocols* TLS 1.2 SSHv2 SNMPv3 *Note: These protocols have not been tested or reviewed by the CMVP or the CAVP. Cryptographic Boundary The Panorama Virtual Appliance is a software cryptographic module and requires an underlying general purpose computer (GPC) environment. The module consists of a GPC (multi-chip standalone embodiment) with the cryptographic boundary defined below. The cryptographic boundary (CB) includes all of the software components of the module, which is included in the file name in Section 11 (Panorama_pc-10.2.3-h1) and also the configuration file that resides on the virtual machine’s virtual disk. The physical perimeter (PP) is defined by the enclosure around the host GPC on which it runs. Figure 1 depicts the boundary and illustrates the hardware components of a GPC. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 9
| PhysicalPort | LogicalInterface | Datathatpassesoverport/interface |
|---|
| Power | Power | Powersupplies |
| Console,GPCI/O | StatusOutput | Self-teststatusoutput |
| Ethernet | Datainput,controlinput,control output,dataoutput,statusoutput | HTTPS,TLS,SNMP,andSSHtrafficdata. |
Table, extracted as text (did not parse into structured rows)
Figure 1 – Cryptographic Boundary 3. Cryptographic Module Interfaces The Panorama VM is designed to operate on a general-purpose computer (GPC) platform. The module supports the following FIPS 140-3 interfaces, which have physical and logical ports consistent with a GPC operating environment. The module does not implement a control output interface. Table 6 –Ports and Interfaces Physical Port Logical Interface Data that passes over port/interface Power Power Power supplies Console, GPC I/O Status Output Self-test status output Ethernet Data input, control input, control HTTPS, TLS, SNMP, and SSH traffic data. output, data output, status output © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 10
| Role | Service | Input | Output |
|---|
| CO | ShowVersion | Querymoduleforversion | Moduleprovidesversion |
| CO,User | Accesswebportal | ConnecttowebportalfromTLS client. | Confirmationofservicevia ConfigurationLogs |
| CO,User | AccessCLI | ConnecttoSSHserverfromSSH client | Confirmationofservicevia ConfigurationLogs |
| CO | SystemProvisioning | Configuringandmanagingsystem configurations(e.g.,IPaddress, systemtime,etc.)viaCLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | PanoramaSoftwareUpdate | Loadingnewimage | Messageoutputnotingversion updatedsuccessfullyviaSystem Logs |
| CO | PanoramaManagerSetup | ConfiguringandmanagingManager configurations(e.g.,HTTPS,NTP,etc.) viaCLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | ManagePanorama AdministrativeAccess | Configuringandmanaging Administrativeconfigurations(e.g., creatinguseraccounts,setting authenticationmethod,etc.)viaCLI orWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | ConfigureHighAvailability | ConfiguringandmanagingHigh Availability(HA)configurationvia CLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | PanoramaCertificate Management | Configuringandmanaging certificatesviaCLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | PanoramaLogSetting | Configuringandmanaginglog settingsviaCLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | PanoramaServerProfiles | ConfiguringandmanagingServer configurations(e.g.SNMP,etc.)via CLIorWebUI | Confirmationofservicevia ConfigurationLogs |
| CO | SetupManagedDevicesand Deployment | ConfiguringandmanagingManaged Devicesconfigurations(e.g., Versions,Licenses,etc.)viaCLIor WebUI | Confirmationofservicevia ConfigurationLogs |
| CO | ConfigureManagedLog Collectors | ConfiguringandmanagingManaged LogCollectorsconfigurationsviaCLI orWebUI | Confirmationofservicevia ConfigurationLogs |
| CO, Unauthenticated | Zeroize | ZeroizefromCLI | ZeroizationIndicator |
Table, extracted as text (did not parse into structured rows)
4. Roles, Services, and Authentication Roles and Services While in the Approved mode of operation, all CO and User services are accessed via SSH or TLS sessions. Approved and allowed algorithms, relevant CSPs and public keys related to these protocols are accessed to support the following services. CSP access by services is further described in the following tables. Table 7 – Roles, Service Commands, Input and Output Show Version Query module for version Module provides version Access web portal Connect to web portal from TLS Confirmation of service via Access CLI Connect to SSH server from SSH Confirmation of service via System Provisioning Configuring and managing system Confirmation of service via CO configurations (e.g., IP address, Configuration Logs system time, etc.) via CLI or WebUI Panorama Software Update Loading new image Message output noting version CO updated successfully via System Panorama Manager Setup Configuring and managing Manager Confirmation of service via via CLI or WebUI Manage Panorama Configuring and managing Confirmation of service via Administrative Access Administrative configurations (e.g., Configuration Logs authentication method, etc.) via CLI or WebUI Configure High Availability Configuring and managing High Confirmation of service via CLI or WebUI Panorama Certificate Configuring and managing Confirmation of service via CO Management certificates via CLI or WebUI Configuration Logs Panorama Log Setting Configuring and managing log Confirmation of service via CO settings via CLI or WebUI Configuration Logs Panorama Server Profiles Configuring and managing Server Confirmation of service via CLI or WebUI Setup Managed Devices and Configuring and managing Managed Confirmation of service via Configure Managed Log Configuring and managing Managed Confirmation of service via or WebUI CO, Zeroize Zeroize from CLI Zeroization Indicator © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 11
| CO,User, Unauthenticated | Self-Test | Runself-testviaCLIorWebUI | OutputresultsviaSystemLogs |
|---|
| CO,User | ShowStatus | ShowstatusviaCLIorWebUI | FIPS-CCModeIndicator |
| CO,User | SystemAudit | ViewsystemauditrecordsviaCLIor WebUI | AuditrecordsviaSystemLogs |
| CO,User | MonitorSystemStatusand Logs | ViewsystemstatusrecordsviaCLIor WebUI | SystemstatusviaSystemLogs |
| CO | PanoramaLogCollectorSetup | ConfiguringandmanagingLog CollectorsconfigurationsviaCLIor WebUI | Confirmationofservicevia ConfigurationLogs. |
| Role | AuthenticationMethod | AuthenticationStrength |
|---|
| CO | MemorizedSecret(Unique Username/password)and/or Single-FactorCryptographic Software(certificatecommon name/publickey-based authentication) | Password-based Minimumlengthiseight1(8)characters(95possiblecharacters).The probabilitythatarandomattemptwillsucceedorafalseacceptance willoccuris1/(958)whichislessthan1/1,000,000. Theprobabilityof successfullyauthenticatingtothemodulewithinoneminuteis 10/(958),whichislessthan1/100,000. Themodule’sconfiguration supportsatmosttenfailedattemptstoauthenticateinaone-minute period. Certificate/Publickey-based Thesecuritymodulessupportpublic-keybasedauthenticationusing RSA2048andcertificate-basedauthenticationusingRSA2048,RSA 3072,RSA4096,ECDSAP-256,P-384,orP-521. Theminimumequivalentstrengthsupportedis112bits. The probabilitythatarandomattemptwillsucceedis1/(2112)whichisless than1/1,000,000. Theprobabilityofsuccessfullyauthenticatingto themodulewithinaoneminuteperiodis10/(2112),whichislessthan 1/100,000. Themodulesupportsatmost10failedattemptsandlocks outafterwards. |
| User | MemorizedSecret(Unique Username/password)and/or Single-FactorCryptographic Software(certificatecommon name/publickey-based authentication) | |
CO, User, Self-Test Run self-test via CLI or WebUI Output results via System Logs Show Status Show status via CLI or WebUI FIPS-CC Mode Indicator System Audit View system audit records via CLI or Audit records via System Logs Monitor System Status and View system status records via CLI or System status via System Logs Panorama Log Collector Setup Configuring and managing Log Confirmation of service via CO Collectors configurations via CLI or Configuration Logs. Assumption of Roles The module supports distinct operator roles. The cryptographic module in Panorama or Management-Only mode enforces the separation of roles using unique authentication credentials associated with operator accounts. The Log Collector mode only supports one role, the Crypto-Officer (CO) role. The module does not provide a maintenance role or bypass capability. Table 8 - Roles and Authentication Role Authentication Method Authentication Strength Minimum length is eight1 (8) characters (95 possible characters). The probability that a random attempt will succeed or a false acceptance Memorized Secret (Unique will occur is 1/(958) which is less than 1/1,000,000. The probability of Username/password) and/or successfully authenticating to the module within one minute is Single-Factor Cryptographic 10/(958), which is less than 1/100,000. The module’s configuration Software (certificate common supports at most ten failed attempts to authenticate in a one-minute Certificate/Public key-based The security modules support public-key based authentication using Memorized Secret (Unique Username/password) and/or The minimum equivalent strength supported is 112 bits. The Single-Factor Cryptographic probability that a random attempt will succeed is 1/(2112) which is less User than 1/1,000,000. The probability of successfully authenticating to name / public key-based the module within a one minute period is 10/(2112), which is less than authentication) 1/100,000. The module supports at most 10 failed attempts and locks out afterwards. Definition of CSPs Modes of Access The following table defines the relationship between access to CSPs and the different module services. The modes of access shown in the table are defined as: In FIPS-CC Mode, the module checks and enforces the minimum password length of eight (8) as specified in SP 800-63B. Passwords are securely stored hashed with salt value, with very restricted access control, and rate limiting mechanism for authentication attempts. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 12
| Service | Description | ApprovedSecurity Functions | | Keysand/or SSPs | Roles | Access rightsto Keys and/or SSPs | Indicator |
|---|
| ShowVersion | Querythemoduleto displaytheversion | N/A | | N/A | CO | N/A | Versiondisplayedvia SystemLogs/CLI/UI |
| Accessweb portal | Connecttomodule’sweb portaltoinvokeservices. (Panoramaor Management-OnlyMode) | RSASigVer(186-4) | | CACertificates | CO | G/R/E/W | SystemLogs |
| | RSASigVer(186-4) | | RSAPublicKeys | | G/R/E/W | |
| | ECDSASigVer(186-4) | | ECDSAPublicKeys | | G/R/E/W | |
| | KAS | KDFTLS | TLSPre-MasterSecret | | G/E/Z | |
| | | | TLSMasterSecret | | G/E/Z | |
| | | CKG, ECDSAKeyGen(FIPS186-4), ECDSAKeyVer(FIPS186-4), KAS-ECC-SSC,KAS-FFC-SSC, SafePrimesKeyGeneration, SafePrimesKeyVerification | TLSDHE/ECDHEPrivate Components | | G/E/Z | |
| | | | TLSDHE/ECDHEPublic Components | | G/E/Z | |
| | KTS | HMAC-SHA2-256 HMAC-SHA2-384 | TLSHMACKeys | | G/E/Z | |
| | | AES-CBC | TLSEncryptionKeys | | G/E/Z | |
| | KTS | AES-GCM | TLSEncryptionKeys | | G/E/Z | |
| | CounterDRBG,ESV | | DRBGSeed DRBGKey DRBGV EntropyInputString | | G/E | |
| AccessCLI | Connecttomodule’sCLIvia SSH | KTS | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | SSHSession AuthenticationKeys | CO, User | G/E/Z | SystemLogs |
| | | AES-CBC AES-CTR | SSHSession EncryptionKeys | | G/E/Z | |
| | KTS | AES-GCM | | | G/E/Z | |
| | KAS | KDFSSH(CVL) | SSHDHE/ECDHE PrivateComponents | | G/E/Z | |
| | | KAS-ECC-SSC KAS-FFC-SSC SafePrimesKeyGeneration SafePrimesKey Verification | SSHDHE/ECDHE PublicComponents | | G/E/R/W/Z | |
| | CounterDRBG,ESV | | DRBGSeed DRBGKey DRBGV EntropyInputString | | G/E | |
Table, extracted as text (did not parse into structured rows)
G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Note: Unless otherwise specified, all services are available in all system modes. If there is a service that is specific to a certain system mode, it is noted in the Description column. Table 9 – Approved Services Functions SSPs rights to Query the module to Version displayed via Show Version N/A N/A CO N/A display the version System Logs / CLI / UI RSA SigVer (186-4) CA Certificates G/R/E/W RSA SigVer (186-4) RSA Public Keys G/R/E/W ECDSA SigVer (186-4) ECDSA Public Keys G/R/E/W TLS Pre-Master Secret G/E/Z KDF TLS TLS Master Secret G/E/Z CKG, TLS DHE/ECDHE Private G/E/Z KAS ECDSA KeyGen (FIPS 186-4), Components Connect to module’s web ECDSA KeyVer (FIPS 186-4), TLS DHE/ECDHE Public Access web Safe Primes Key Generation, G/E/Z CO System Logs portal Safe Primes Key Verification (Panorama or G/E/Z DRBG Seed DRBG Key Counter DRBG, ESV G/E DRBG V Entropy Input String SSH Session Authentication Keys SSH Session G/E/Z Encryption Keys Private Components Connect to module’s CLI via CO, Safe Primes Key Generation G/E/R/W/Z Public Components Safe Primes Key DRBG Seed DRBG Key Counter DRBG, ESV G/E DRBG V Entropy Input String © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 13
| System Provisioning | Performpanorama licensing,diagnostics, debugfunctions,manage Panoramasupport informationandswitch betweenPanorama Management-only,and Loggermodes. (Panoramaor Management-OnlyMode) | N/A | | N/A | CO | N/A | Systemand Configurationlogs |
|---|
| Panorama Software Update | Downloadandinstall softwareupdates | RSASigVer(FIPS186-4) | | PublicKeyfor SoftwareLoadTest | CO | W/E | Systemand Configurationlogs |
| Panorama ManagerSetup | Presentsconfiguration optionsformanagement interfacesand communicationforpeer services(e.g.,SNMP, RADIUS). Import,Export,Save,Load, revertandvalidate Panoramaconfigurations andstaterole (Panoramaor Management-OnlyMode) | CKG RSAKeyGen(FIPS186-4) RSASigGen(FIPS186-4) | | RSAPrivateKeys | CO | G/W/E | Systemand Configurationlogs |
| | CKG ECDSAKeyGen (FIPS186-4) ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | | G/W/E | |
| | RSASigVer(FIPS186-4) | | RSAPublicKeys | | G/R/E/W | |
| | ECDSASigVer(FIPS186-4) | | ECDSAPublicKeys | | G/R/E/W | |
| | KDFSNMP(CVL) | | SNMPv3Authentication Secret | | W/E | |
| | | | SNMPv3PrivacySecret | | W/E | |
| | HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 | | AuthenticationKey | | G/E/Z | |
| | AES-CFB128 | | SessionKey | | G/E/Z | |
| | RSASigVer(FIPS186-4) ECDSASigVer (FIPS186-4) | | CACertificates | | G/R/E/W | |
| | KAS | KDFTLS | TLSPre-MasterSecret | | G/E/Z | |
| | | | TLSMasterSecret | | G/E/Z | |
| | | CKG, ECDSAKeyGen(FIPS186-4), ECDSAKeyVer(FIPS186-4), KAS-ECC-SSC,KAS-FFC-SSC, SafePrimesKeyGeneration, SafePrimesKeyVerification | TLSDHE/ECDHEPrivate Components | | G/E/Z | |
| | | | TLSDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | KTS | HMAC-SHA2-256 HMAC-SHA2-384 | TLSHMACKeys | | G/E/Z | |
| | | AES-CBC | TLSEncryptionKeys | | G/E/Z | |
| | KTS | AES-GCM | TLSEncryptionKeys | | G/E/Z | |
| | KTS | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | SSHSession AuthenticationKeys | | G/E/Z | |
| | | AES-CBC,AES-CTR | SSHSessionEncryption Keys | | G/E/Z | |
| | KTS | AES-GCM | | | | |
| | KAS | KDFSSH KAS-ECC-SSC KAS-FFC-SSC SafePrimesKeyGeneration, SafePrimesKeyVerification | SSHDHE/ECDHEPrivate Components | | G/E/Z | |
| | | | SSHDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | CounterDRBG,ESV | | DRBGSeed DRBGKey | | G/E | |
Table, extracted as text (did not parse into structured rows)
Perform panorama debug functions, manage Panorama support information and switch Provisioning Configuration logs Logger modes. (Panorama or Download and install Public Key for System and Software RSA SigVer (FIPS 186-4) CO W/E software updates Software Load Test Configuration logs CKG RSA Private Keys G/W/E RSA KeyGen (FIPS 186-4) RSA SigGen (FIPS 186-4) CKG ECDSA Private Keys G/W/E ECDSA KeyGen ( FIPS 186-4) ECDSA SigGen (FIPS 186-4) RSA SigVer (FIPS 186-4) RSA Public Keys G/R/E/W ECDSA SigVer (FIPS 186-4) ECDSA Public Keys G/R/E/W SNMPv3 Authentication W/E SNMPv3 Privacy Secret W/E HMAC-SHA-1 Authentication Key G/E/Z AES-CFB128 Session Key G/E/Z RSA SigVer (FIPS 186-4) ECDSA SigVer CA Certificates G/R/E/W Presents configuration (FIPS 186-4) options for management interfaces and TLS Pre-Master Secret G/E/Z communication for peer KDF TLS TLS Master Secret G/E/Z RADIUS). CKG, TLS DHE/ECDHE Private Manager Setup Configuration logs revert and validate ECDSA KeyVer (FIPS 186-4), TLS DHE/ECDHE Public and state role Safe Primes Key Generation, G/E/R/W/Z Safe Primes Key Verification AES-CBC, AES-CTR SSH Session Encryption G/E/Z KAS KDF SSH SSH DHE/ECDHE Private G/E/Z Safe Primes Key Generation, SSH DHE/ECDHE Public G/E/R/W/Z Safe Primes Key Verification Components DRBG Seed Counter DRBG, ESV DRBG Key G/E © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 14
| | | DRBGV | | | |
|---|
| | | EntropyInputString | | | |
| Manage Panorama Administrative Access | Defineaccesscontrol methodsviaadminprofiles, configureadministrators andpasswordprofiles Configurelocaluser database,authentication profiles,sequenceof methodsandaccess domains | N/A | CO,UserPassword | CO | G/E/W | Systemand Configurationlogs |
| | RSASigVer(FIPS186-4) | SSHClientPublicKey | | W/E | |
| | RSASigVer(FIPS186-4) ECDSASigVer(FIPS186-4) | SSHHostPublicKey | | G/R/E/W | |
| ConfigureHigh Availability | ConfigureHighAvailability communicationsettings (Panoramaor Management-OnlyMode) | RSASigVer(FIPS186-4) | RSAPublicKey | CO | G/R/E/W | ConfigurationLogs |
| | ECDSASigVer(FIPS186-4) | ECDSAPublicKey | | G/R/E/W | |
| Panorama Certificate Management | ManageRSA/ECDSA certificatesandprivate keys,certificateprofiles, revocationstatus,and usage;showstatus. | ECDSASigGen (FIPS186-4) RSASigGen (FIPS186-4) | RSAPrivateKeys ECDSAPrivateKeys | CO | G/R/W/E | ConfigurationLogs |
| | ECDSASigVer (FIPS186-4) RSASigVer (FIPS186-4) | RSAPublicKeys ECDSAPublicKeys | | G/R/W/E | ConfigurationLogs |
| | CounterDRBG,ESV | DRBGSeed DRBGKey DRBGV EntropyInputString | | G/E | SystemLogs |
| PanoramaLog Setting | Configurelogforwarding (Panoramaor Management-OnlyMode) | N/A | N/A | CO | N/A | ConfigurationLogs |
| Panorama ServerProfiles | Configurecommunication parametersand informationforpeer servers (Panoramaor Management-OnlyMode) | KDFSNMP(CVL) | SNMPv3Authentication Secret | CO | W/E | SystemLogs |
| | | SNMPv3PrivacySecret | | W/E | |
| | HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 | AuthenticationKey | | G/E/Z | |
| | AES-CFB128 | SessionKey | | G/E/Z | |
| SetupManaged Devicesand Deployment | Set-upanddefinemanaged devices,devicegroupsfor firewalls Configuredevice deploymentapplications andlicenses Viewcurrentdeployment informationonthe managedfirewalls.Italso allowsyoutomanage software/firmwareversions andscheduleupdateson themanagedfirewallsand managedlogcollectors. (Panoramaor Management-OnlyMode) | N/A | N/A | CO | N/A | ConfigurationLogs |
| Configure ManagedLog Collectors | Setupandmanageother LogCollectormanagement, communicationandstorage settings Viewcurrentdeployment informationonthe managedLogCollectors.It | N/A | CO,UserPassword | CO | G/E/W | Systemand Configurationlogs |
Table, extracted as text (did not parse into structured rows)
DRBG V Entropy Input String Define access control N/A CO, User Password G/E/W methods via admin profiles, configure administrators RSA SigVer (FIPS 186-4) SSH Client Public Key W/E Configure local user CO Administrative Configuration logs database, authentication RSA SigVer (FIPS 186-4) Access SSH Host Public Key G/R/E/W profiles, sequence of ECDSA SigVer (FIPS 186-4) Configure High Availability RSA SigVer (FIPS 186-4) RSA Public Key G/R/E/W communication settings Configure High CO Configuration Logs Availability ECDSA SigVer (FIPS 186-4) ECDSA Public Key G/R/E/W (Panorama or Management-Only Mode) ECDSA SigGen (FIPS 186-4) RSA Private Keys G/R/W/E Configuration Logs RSA SigGen ECDSA Private Keys (FIPS 186-4) Manage RSA/ECDSA ECDSA SigVer Panorama certificates and private (FIPS 186-4) RSA Public Keys G/R/W/E Configuration Logs Management revocation status, and (FIPS 186-4) usage; show status. DRBG Seed DRBG Key Counter DRBG, ESV G/E System Logs DRBG V Entropy Input String Configure log forwarding Panorama Log N/A N/A CO N/A Configuration Logs Management-Only Mode) SNMPv3 Authentication W/E KDF SNMP (CVL) Secret Configure communication SNMPv3 Privacy Secret W/E parameters and information for peer HMAC-SHA-1 Authentication Key G/E/Z Server Profiles AES-CFB128 Session Key G/E/Z Set-up and define managed devices, device groups for Configure device deployment applications and licenses Setup Managed View current deployment Devices and information on the N/A N/A CO N/A Configuration Logs allows you to manage software/firmware versions and schedule updates on the managed firewalls and managed log collectors. (Panorama or Management-Only Mode) Setup and manage other Log Collector management, Configure communication and storage System and Managed Log settings N/A CO, User Password CO G/E/W Configuration logs Collectors View current deployment information on the managed Log Collectors. It © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 15
| alsoallowsyoutomanage software/firmwareversions andscheduleupdateson managedlogcollectors. (Panoramaor Management-OnlyMode) | | | | | | |
|---|
| Zeroize | OverwriteallCSPs | N/A | | AllkeysandSSPs | CO | Z | ZeroizationIndicator |
| Self-Test | Runpowerupself-testson demandbypowercycling themodule. | N/A | | SoftwareIntegrity VerificationKey | CO, User | E | SystemLogs |
| ShowStatus | Viewstatusofthemodule | N/A | | N/A | CO, User | N/A | FIPS-CCMode Indicator |
| SystemAudit | Allowsreviewoflimited configurationandsystem statusviaSNMPv3,logs, dashboard,showstatus, andconfigurationscreens. COOnly:Provides configurationcommit capability. (Panoramaor Management-OnlyMode) | N/A | | N/A | CO, User | N/A | SystemLogs |
| Monitor SystemStatus andLogs | Reviewsystemstatusvia thepanoramasystemCLI, dashboardandlogs;show status. (Panoramaor Management-OnlyMode) | N/A | | N/A | CO, User | N/A | SystemLogs |
| PanoramaLog CollectorSetup | Presentsconfiguration optionsformanagement interfacesand communicationforpeer services Import,Export,Save,Load, revertandvalidate Panoramaconfigurations andstate (LogCollectormode) | CKG RSAKeyGen(FIPS186-4) RSASigGen(FIPS186-4) | | RSAPrivateKeys | CO | G/W/E | Systemand Configurationlogs |
| | CKG ECDSAKeyGen (FIPS186-4) ECDSASigGen (FIPS186-4) | | ECDSAPrivateKeys | | G/W/E | |
| | RSASigVer(FIPS186-4) | | RSAPublicKeys | | G/R/E/W | |
| | ECDSASigVer(FIPS186-4) | | ECDSAPublicKeys | | G/R/E/W | |
| | KAS | KDFTLS | TLSPre-MasterSecret | | G/E/Z | |
| | | | TLSMasterSecret | | G/E/Z | |
| | | CKG, ECDSAKeyGen(FIPS186-4), ECDSAKeyVer(FIPS186-4), KAS-ECC-SSC,KAS-FFC-SSC, SafePrimesKeyGeneration, SafePrimesKeyVerification | TLSDHE/ECDHEPrivate Components | | G/E/Z | |
| | | | TLSDHE/ECDHEPublic Components | | G/E/R/W/Z | |
| | KTS | HMAC-SHA2-256 HMAC-SHA2-384 | TLSHMACKeys | | G/E/Z | |
| | | AES-CBC | TLSEncryptionKeys | | G/E/Z | |
| | KTS | AES-GCM | TLSEncryptionKeys | | G/E/Z | |
| | KTS | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | SSHSession AuthenticationKeys | | G/E/Z | |
| | | AES-CBC,AES-CTR | SSHSessionEncryption Keys | | G/E/Z | |
| | KTS | AES-GCM | | | | |
| | KAS | KDFSSH(CVL) KAS-ECC-SSC KAS-FFC-SSC | SSHDHE/ECDHEPrivate Components | | G/E/Z | |
Table, extracted as text (did not parse into structured rows)
also allows you to manage software/firmware versions and schedule updates on managed log collectors. (Panorama or Management-Only Mode) Zeroize Overwrite all CSPs N/A All keys and SSPs CO Z Zeroization Indicator Run power up self-tests on Self-Test demand by power cycling N/A E System Logs Verification Key User the module. CO, FIPS-CC Mode Show Status View status of the module N/A N/A N/A Allows review of limited configuration and system status via SNMPv3, logs, and configuration screens. System Audit N/A N/A N/A System Logs configuration commit (Panorama or Management-Only Mode) Review system status via the panorama system CLI, and Logs (Panorama or Management-Only Mode) CKG RSA Private Keys G/W/E RSA KeyGen (FIPS 186-4) RSA SigGen (FIPS 186-4) CKG ECDSA Private Keys G/W/E ECDSA KeyGen ( FIPS 186-4) ECDSA SigGen (FIPS 186-4) RSA SigVer (FIPS 186-4) RSA Public Keys G/R/E/W ECDSA SigVer (FIPS 186-4) ECDSA Public Keys G/R/E/W TLS Pre-Master Secret G/E/Z KDF TLS TLS Master Secret G/E/Z Presents configuration options for management CKG, TLS DHE/ECDHE Private interfaces and ECDSA KeyGen (FIPS 186-4), Components communication for peer ECDSA KeyVer (FIPS 186-4), TLS DHE/ECDHE Public Panorama Log Safe Primes Key Generation, CO G/E/R/W/Z Collector Setup Safe Primes Key Verification revert and validate Panorama configurations HMAC-SHA2-256 TLS HMAC Keys G/E/Z (Log Collector mode) HMAC-SHA-1 SSH Session G/E/Z AES-CBC, AES-CTR SSH Session Encryption G/E/Z KDF SSH (CVL) SSH DHE/ECDHE Private G/E/Z © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 16
| SafePrimesKeyGeneration, SafePrimesKeyVerification | | |
|---|
| CounterDRBG,ESV | | DRBGSeed DRBGV DRBGKey EntropyInputString | G/E |
Safe Primes Key Generation, Safe Primes Key Verification DRBG Seed DRBG V Counter DRBG, ESV G/E DRBG Key Entropy Input String Note: Configuration/System Logs for Approved services above will indicate FIPS-CC mode is enabled and that the service succeeded.
- Software/Firmware Security The module performs the Software Integrity test by using HMAC-SHA-256 (HMAC Cert. #A2907) during the Pre-Operational Self-Test. In addition, the module also conducts a software load test by using RSA 2048 with SHA-256 (Cert. #A2907) for the new validated software to be uploaded into the module. Any software loaded into this module that is not shown on the module certificate is out of scope of this validation, and requires a separate FIPS 140-3 validation. The pre-operational self-tests can be initiated by power cycling the module. When this is performed, the module automatically runs the cryptographic algorithm self-tests in addition to the pre-operational software integrity test.
- Operational Environment The module is a modifiable operational environment as per FIPS 140-3 Level 1 specifications. The hypervisor environment provides an isolated operating environment and is the single operator of the virtual machine. The tested operating environments isolate virtual systems into separate isolated process spaces. Each process space is logically separated from all other processes by the operating environments software and hardware. The module functions entirely within the process space of the isolated system as managed by the single operational environment. This implicitly meets the FIPS 140-3 requirement that only one (1) entity at a time can use the cryptographic module.
- Physical Security The module is a software only module; FIPS 140-3 physical security requirements are not applicable.
- Non-Invasive Security There are currently no defined Approved non-invasive attack mitigation test metrics in SP 800-140F.
- Sensitive Security Parameters Management The following table details all the sensitive security parameters utilized by the module. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 17
| Key/SSP/Name/Type | Streng th | Security Functionand Cert. Number | Generati on | Import/Exp ort | Establishm ent | Storage | Zeroization1 | Use&RelatedKeys |
|---|
| CACertificates | 112-256 bits | RSASigVer(FIPS 186-4) ECDSASigVer (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD– Zeroize Service RAM-Zeroize atsession termination | ECDSA/RSAPublickey- UsedtotrustarootCA intermediateCAand leaf/endentity certificates (RSA2048,3072,and 4096bits) (ECDSAP-256,P-384, andP-521) |
| RSAPublicKeys | 112-150 bits | RSASigVer (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encryptedor Plaintext TLShandshake | N/A | HDD/RAM– plaintext | Zeroize Service | RSApublickeys managedascertificates fortheverificationof signatures, establishmentofTLS, operatorauthentication andpeer authentication. (RSA2048,3072,or 4096-bit) |
| RSAPrivateKeys | 112-150 bits | RSASigGen (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD– Zeroize Service RAM-Zeroize atsession termination | RSAPrivatekeysfor generationof signatures, authenticationorkey establishment. (RSA2048,3072,or 4096-bit) |
| ECDSAPublicKeys | 128-256 bits | ECDSASigVer (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encryptedor Plaintext TLShandshake | N/A | HDD/RAM– plaintext | Zeroize Service | ECDSApublickeys managedascertificates fortheverificationof signatures, establishmentofTLS, operatorauthentication andpeer authentication. (ECDSAP-256,P-384, orP-521) |
| ECDSAPrivateKeys | 128-256 bits | ECDSASigGen (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | TLSorSSH SessionKey Encrypted | N/A | HDD/RAM– plaintext | HDD– Zeroize Service RAM-Zeroize atsession termination | ECDSAPrivatekeyfor generationofsignatures andauthentication (P-256,P-384,or P-521) |
| TLSDHE/ECDHE PrivateComponents | 112-256 bits | KAS-ECC-SSC KAS-FFC-SSC Cert.#A2907 | DRBG,SP 800-56ARev. 3 | N/A | N/A | RAM-plaintext | Zeroizeat session termination | KAS-FFCorKAS-ECC Ephemeralvaluesused inkeyagreement (KAS-FFCMODP-2048, KAS-ECCP-256,P-384, P-521) |
| TLSDHE/ECDHEPublic Components | 112-256 bits | KAS-ECC-SSC KAS-FFC-SSC Cert.#A2907 | DRBG,SP 800-56ARev. 3 | Plaintext-TLS handshake | N/A | RAM-plaintext | Zeroizeat session termination | KAS-FFCorKAS-ECC Ephemeralvaluesused inkeyagreement (KAS-FFCMODP-2048, KAS-ECCP-256,P-384, P-521) |
| TLSPre-MasterSecret | N/A | KDFTLS Cert.#A2907 | KASSP 800-56ARev. 3 | N/A | N/A | RAM–plaintext | Zeroizeat session termination | Secretvalueusedto derivetheTLSMaster Secretalongwithclient andserverrandom nonces |
| TLSMasterSecret | N/A | KDFTLS Cert.#A2907 | KDFTLS | N/A | N/A | RAM–plaintext | Zeroizeat session termination | Secretvalueusedto derivetheTLSsession keys |
Table, extracted as text (did not parse into structured rows)
Table 10 – SSPs ECDSA/RSA Public key Used to trust a root CA RSA SigVer (FIPS HDD – intermediate CA and TLS or SSH leaf /end entity at session RSA public keys managed as certificates for the verification of RSA SigVer Session Key and peer RSA Private keys for generation of RSA SigGen TLS or SSH signatures, at session managed as certificates for the verification of and peer ECDSA Private key for ECDSA SigGen TLS or SSH generation of signatures at session Ephemeral values used Ephemeral values used Secret value used to KAS SP Zeroize at derive the TLS Master KDF TLS TLS Pre-Master Secret N/A 800-56A Rev. N/A N/A RAM – plaintext session Secret along with client
3 termination and server random
Zeroize at Secret value used to KDF TLS TLS Master Secret N/A KDF TLS N/A N/A RAM – plaintext session derive the TLS session © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 18
| TLSEncryptionKeys | 128or256 bits | AES-CBCor AES-GCM Cert.#A2907 | KDFTLS | N/A | TLS,KASSP 800-56ARev.3 | RAM-plaintext | Zeroizeat session termination | AES(128or256bit) keysusedinTLS connections(GCM; CBC) |
|---|
| TLSHMACKeys | 256bits | HMAC-SHA2-256 HMAC-SHA2-384 Cert.#A2907 | KDFTLS | N/A | TLS,KASSP 800-56ARev.3 | RAM-plaintext | Zeroizeat session termination | HMACkeysusedinTLS connections(256,384) (256,384bits) |
| SSHDHE/ECDHE PrivateComponents | 112-256 bits | KAS-ECC-SSC KAS-FFC-SSC Cert.#A2907 | DRBG,SP 800-56ARev. 3 | N/A | N/A | RAM-plaintext | Zeroizeat session termination | KAS-FFCorKAS-ECC publiccomponent (KAS-FFCMODP-2048, KAS-ECCP-256, KAS-ECCP-384, KAS-ECCP-521) |
| SSHDHE/ECDHEPublic Components | 112-256 bits | KAS-ECC-SSC KAS-FFC-SSC Cert.#A2907 | DRBG,SP 800-56ARev. 3 | PlaintextSSH handshake | N/A | RAM-plaintext | Zeroizeat session termination | KAS-FFCorKAS-ECC publiccomponent (KAS-FFCGroup14, KAS-ECCP-256, KAS-ECCP-384, KAS-ECCP-521) |
| SSHHostPublicKey | 112-256 bits | RSASigVer (FIPS186-4) ECDSASigVer (FIPS186-4) Cert.#A2907 | DRBG,FIPS 186-4 | N/A | N/A | HDD/RAM– plaintext | Zeroize Service | SSHHostPublicKey (RSA2048,RSA3072, RSA4096,ECDSA P-256,P-384,orP-521) |
| SSHClientPublicKey | 112-150 bits | RSASigVer (FIPS186-4) Cert.#A2907 | N/A | Encryptedvia SSHorTLS | N/A | HDD/RAM– plaintext | Zeroize Service | PublicRSAkeyusedto authenticateclient. (RSA2048,3072,and 4096bits) |
| SSHSessionEncryption Keys | 128-256 bits | AES-CBC, AES-CTR,or AES-GCM Cert.#A2907 | KDFSSH | N/A | SSH,KASSP 800-56ARev.3 | RAM-plaintext | Zeroizeat session termination | UsedinallSSH connectionstothe securitymodule’s commandlineinterface. (128,192,or256bits: CBCorCTR) (128or256bits:GCM) |
| SSHSession AuthenticationKeys | 160-256 bits | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 Cert.#A2907 | KDFSSH | N/A | SSH,KASSP 800-56ARev.3 | RAM-plaintext | Zeroizeat session termination | Authenticationkeys usedinallSSH connectionstothe securitymodule’s commandlineinterface (HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-512) (160,256,512bits) |
| Softwareintegrity verificationkey (Note:Thisisnotconsidered anSSP) | 128bits | HMAC-SHA2-256, ECDSASigVer (FIPS186-4) Cert.#A2907 | N/A | N/A | N/A | HDD-plaintext | N/A | Usedtocheckthe integrityof crypto-relatedcode. (HMAC-SHA-256and ECDSAP-256) |
| Publickeyforsoftware contentloadtest | 112bits | RSASigVer (FIPS186-4) Cert.#A2907 | N/A | N/A | N/A | HDD-plaintext | N/A | Usedtoauthenticate software/firmwareand contenttobeinstalled onthemodule(RSA 2048withSHA-256) |
| CO,UserPassword | N/A | SHA2-256 Cert.#A2907 | External | Encryptedvia SSHorTLS | N/A | HDD-apassword hash(SHA2-256) | ZeroizeService | Authenticationstring withaminimumlength ofeight(8)characters. |
| ProtocolSecrets | N/A | N/A | N/A | Encryptedvia SSHorTLS | N/A | HDD/RAM– plaintext | ZeroizeService | SecretsusedbyRADIUS (8charactersminimum) |
| EntropyInputString | 256bits | CKG(vendor affirmed),Counter DRBG Cert.#A2907 | Entropyas per SP800-90B | N/A | N/A | RAM-plaintext | Powercycle | Entropyinputstring comingfromthe entropysource Inputlength=384bits |
| DRBGSeed | 256bits | CKG(vendor affirmed),Counter DRBG | Entropyas per SP800-90B | N/A | N/A | RAM-Plaintext | Powercycle | DRBGseedcomingfrom theentropysource |
Table, extracted as text (did not parse into structured rows)
800-56A Rev. 3 public component Plaintext SSH public component RSA SigVer (FIPS 186-4) SSH Host Public Key SSH Host Public Key N/A N/A Public RSA key used to RSA SigVer
112 - 150 Encrypted via HDD/RAM – Zeroize authenticate client.
SSH Client Public Key (FIPS 186-4) N/A N/A
4096 bits)
Table, extracted as text (did not parse into structured rows)
Used in all SSH connections to the Zeroize at security module’s KDF SSH N/A RAM - plaintext session command line interface. Authentication keys used in all SSH connections to the Zeroize at security module’s KDF SSH N/A RAM - plaintext session command line interface Used to check the integrity of verification key ECDSA SigVer (Note: This is not considered (FIPS 186-4) an SSP) Cert. #A2907 Used to authenticate Public key for software content load test Cert. #A2907 on the module (RSA Authentication string SHA2-256 Encrypted via HDD - a password CO, User Password N/A External N/A Zeroize Service with a minimum length of eight (8) characters. Encrypted via HDD/RAM – Secrets used by RADIUS Protocol Secrets N/A N/A N/A N/A Zeroize Service Entropy input string Entropy as coming from the Entropy Input String 256 bits per N/A N/A RAM - plaintext Power cycle entropy source Input length = 384 bits CKG (vendor Entropy as DRBG seed coming from DRBG Seed 256 bits affirmed), Counter per N/A N/A RAM - Plaintext Power cycle the entropy source © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 19
| | Cert.#A2907 | | | | | | Seedlength=384bits |
|---|
| DRBGKey | 256bits | CKG(vendor affirmed),Counter DRBG Cert.#A2907 | Entropyas per SP800-90B | N/A | N/A | RAM-plaintext | Powercycle | AES256CTRDRBG stateKeyusedinthe generationofarandom values |
| DRBGV | 128bits | CKG(vendor affirmed),Counter DRBG Cert.#A2907 | Entropyas per SP800-90B | N/A | N/A | RAM-plaintext | Powercycle | AES256CTRDRBG stateVusedinthe generationofarandom values |
| SNMPv3Authentication Secret | N/A | KDFSNMP Cert.#A2907 | N/A | Encryptedvia TLS/SSH | N/A | HDD/RAM– plaintext | ZeroizeService | UsedtosupportSNMPv3 services (Minimum8characters) |
| SNMPv3PrivacySecret | N/A | KDFSNMP Cert.#A2907 | N/A | Encryptedvia TLS/SSH | N/A | HDD/RAM– plaintext | ZeroizeService | UsedtosupportSNMPv3 services (Minimum8characters) |
| SNMPv3Authentication Key | 160-256 bits | HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 Cert.#A2907 | KDFSNMP | N/A | N/A | HDD/RAM- Plaintext | Zeroize Service | HMAC–SHA-1/224/256 /384/512 Authenticationprotocol key(160bits) |
| SNMPv3SessionKey | 128-256 bits | AES-CFB128 Cert.#A2907 | KDFSNMP | N/A | N/A | HDD/RAM- Plaintext | Zeroize Service | Privacyprotocol encryptionkey (AES-CFB128) |
| EntropySource | Minimumnumberofbitsofentropy | Details |
|---|
| PaloAltoNetworksDRNGEntropy Source | 256bits | ESVCert.#E69 Entropysourceprovidesfullentropy, whichisprovidedinthe384bitseed. |
Seed length = 384 bits Entropy as DRBG state Key used in the generation of a random SP 800-90B Entropy as DRBG state V used in the generation of a random SP 800-90B SNMPv3 Authentication Used to support SNMPv3 KDF SNMP Encrypted via HDD/RAM
- (Minimum 8 characters) Used to support SNMPv3 KDF SNMP Encrypted via HDD/RAM
- (Minimum 8 characters) KDF SNMP N/A N/A Privacy protocol SNMPv3 Session Key KDF SNMP N/A N/A encryption key Note: SSPs are implicitly zeroized when power is lost, or explicitly zeroized by the zeroize service. In the case of implicit zeroization, the SSPs are implicitly overwritten with random values due to their ephemeral memory being reset upon power loss. For the zeroization service and zeroization at session termination, the SSP's memory location is overwritten with random values. The module utilizes the following entropy source, which is internal to the physical perimeter of the host GPC. Table 11 - Non-Deterministic Random Number Generation Specification Entropy Source Minimum number of bits of entropy Details Palo Alto Networks DRNG Entropy 256 bits Source Entropy source provides full entropy, which is provided in the 384 bit seed. 10. Self-Tests The cryptographic module performs the following tests below. The operator can command the module to perform the pre-operational and cryptographic algorithm self-tests by cycling power of the module. The pre-operational and conditional self-tests are performed automatically and do not require any additional operator action. Pre-operational Self-Tests Pre-operational Software Integrity Test
- Verified with HMAC-SHA-256 and ECDSA P-256 © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 20
Note: the ECDSA and HMAC-SHA-256 KATs are performed prior to the Software integrity test Conditional self-tests Cryptographic algorithm self-tests
- AES 128-bit ECB Encrypt Known Answer Test
- AES 128-bit ECB Decrypt Known Answer Test
- AES 128-bit CMAC Known Answer Test*
- AES 256-bit GCM Encrypt Known Answer Test
- AES 256-bit GCM Decrypt Known Answer Test
- AES 192-bit CCM Encrypt Known Answer Test*
- AES 192-bit CCM Decrypt Known Answer Test *
- RSA 2048-bit PKCS#1 v1.5 with SHA-256 Sign Known Answer Test
- RSA 2048-bit PKCS#1 v1.5 with SHA-256 Verify Known Answer Test
- RSA 2048-bit Encrypt Known Answer Test*
- RSA 2048-bit Decrypt Known Answer Test*
- ECDSA P-256 with SHA-512 Sign Known Answer Test
- ECDSA P-256 with SHA-512 Verify Known Answer Test
- HMAC-SHA-1 Known Answer Test
- HMAC-SHA-256 Known Answer Test
- HMAC-SHA-384 Known Answer Test
- HMAC-SHA-512 Known Answer Test
- SHA-1 Known Answer Test
- SHA-256 Known Answer Test
- SHA-384 Known Answer Test
- SHA-512 Known Answer Test
- DRBG SP 800-90Arev1 Instantiate/Generate/Reseed Known Answer Tests
- SP 800-90Arev1 Instantiate/Generate/Reseed Section 11.3 Health Tests
- SP 800-56Ar3 KAS-FFC-SSC 2048-bit Known Answer Test
- SP 800-56Ar3 KAS-ECC-SSC P-256 Known Answer Test
- SP 800-135rev1 TLS 1.2 with SHA-256 KDF Known Answer Test
- SP 800-135rev1 SSH KDF with SHA-256 Known Answer Test
- SP 800-135rev1 IKEv2 KDF Known Answer Test*
- SP 800-90B RCT/APT Health Tests on Entropy Source Note: The SP 800-90B Health Tests are implemented by the entropy source. *Note: Supported by the module cryptographic implementation, but only utilized for CAST Conditional Pairwise Consistency Self-Tests
- RSA Pairwise Consistency Test
- ECDSA/KAS-ECC Pairwise Consistency Test
- KAS-FFC Pairwise Consistency Test Conditional Software Load test
- Software Load Test
- Verify RSA 2048 with SHA-256 signature on software at time of load Conditional Critical Functions Tests
- SP 800-56A Rev. 3 Assurance Tests (Based on Sections 5.5.2, 5.6.2, and 5.6.3) Error Handling In the event of a conditional test failure, the module will output a description of the error. These are summarized below. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 21
| CauseofError | ErrorStateIndicator |
|---|
| ConditionalCryptographicAlgorithmSelf-TestorSoftware IntegrityTestFailure | FIPS-CCmodefailure. <Algorithmtest>failed. |
| ConditionalPairwiseConsistencyorCriticalFunctionsTest Failure | Systemlogprintsanerrormessage. |
| ConditionalSoftwareLoadTestFailure | SystemprintsInvalidimagemessage. |
Table 12 - Errors and Indicators Cause of Error Error State Indicator Conditional Cryptographic Algorithm Self-Test or Software FIPS-CC mode failure. <Algorithm test> failed. Integrity Test Failure Conditional Pairwise Consistency or Critical Functions Test System log prints an error message. Conditional Software Load Test Failure System prints Invalid image message.
- Life-cycle Assurance The vendor provided life-cycle assurance documentation describes configuration management, design, finite state model, development, testing, delivery & operation, end of life procedures, and guidance. For details regarding the approved mode of operation, see “Approved Mode of Operation''. For details regarding secure installation, initialization, startup, and operation of the module, see below. Installation Instructions The module can be retrieved by downloading Panorama_pc-10.2.3-h1 Palo Alto Network provides an Administrator Guide for additional information noted in the “References” section of this Security Policy. The module design corresponds to the module security rules. Module Enforced Security Rules This section documents the security rules enforced by the cryptographic module to implement the security requirements of this FIPS 140-3 Level 1 module.
- The cryptographic module shall provide distinct operator roles. When the module has not been placed in a valid role, the operator shall not have access to any cryptographic services.
- The cryptographic module shall clear previous authentications on power cycle.
- The module shall support the generation of key material with the approved DRBG. The entropy provided must be greater than or equal to the strength of the key being generated.
- Data output shall be inhibited during self-tests and error states.
- Processes performing key generation and zeroization processes shall be logically isolated from the logical data output paths.
- The module does not output intermediate key generation values.
- Status information output from the module shall not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
- There are no restrictions on which keys or CSPs are zeroized by the zeroization service.
- The module maintains separation between concurrent operators.
- The module does not support a maintenance interface or role.
- The module does not have any external input/output devices used for entry/output of data.
- The module does not enter or output plaintext CSPs.
- The cryptographic module provides identity-based authentication. © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 22
Vendor Imposed Security Rules In FIPS-CC mode, the following rules shall apply:
- When FIPS-CC mode is enabled, the operator shall not install plugins. a. Checked via CLI using “show plugins installed”
- When FIPS-CC mode is enabled, the operator shall not use TACACS+. RADIUS may be used but must be protected by TLS protocol. a. Checked via CLI using “show deviceconfig” command Key to Entity The cryptographic module associates all keys (secret, private, or public) stored within, entered into or output from the module with authenticated operators of the module. Keys stored within the module are only made available to authenticated operators via TLS or SSH. Keys are only input or output from the module by the authenticated operator via a SSH or TLS protected communication. Any attempt to intervene in the key to entity relationship would require defeating the module TLS or SSH encryption and authentication/integrity mechanism.
- Mitigation of Other Attacks This module is not designed to mitigate other attacks outside the scope of FIPS 140-3.
- References [FIPS 140-3] FIPS Publication 140-3 Security Requirements for Cryptographic Modules [AGD] Panorama Administrator’s Guide Version 10.2
- Definitions and Acronyms AES – Advanced Encryption Standard CA – Certificate Authority CLI – Command Line Interface CO – Crypto-Officer CSP – Critical Security Parameter CVL – Component Validation List DB9 – D-sub series, E size, 9 pins DES – Data Encryption Standard DH – Diffie-Hellman DRBG – Deterministic Random Bit Generator EDC – Error Detection Code ECDH – Elliptical Curve Diffie-Hellman ECDSA – Elliptical Curve Digital Signature Algorithm FIPS – Federal Information Processing Standard HMAC – (Keyed) Hashed Message Authentication Code KDF – Key Derivation Function LED – Light Emitting Diode RJ45 – Networking Connector © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 23
RNG –Random number generator RSA
- Algorithm developed by Rivest, Shamir and Adleman SHA
- Secure Hash Algorithm SNMP
- Simple Network Management Protocol SSH
- Secure Shell TLS
- Transport Layer Security USB
- Universal Serial Bus VGA
- Video Graphics Array © 2024 Palo Alto Networks, Inc. Panorama VM 10.2 Security Policy 24