| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 10/10/2029 |
| Caveat | Interim validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys) |
| Vendor | Palo Alto Networks, Inc. |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | A2999 |
| AES-CTR | A2999 |
| AES-ECB | A2999 |
| AES-GCM | A2999 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2873 |
| Counter DRBG | A1362 |
| Counter DRBG | A2999 |
| ECDSA KeyGen (FIPS186-4) | A2999 |
| ECDSA KeyVer (FIPS186-4) | A2999 |
| ECDSA SigGen (FIPS186-4) | A2999 |
| ECDSA SigVer (FIPS186-4) | A2999 |
| HMAC-SHA-1 | A2999 |
| HMAC-SHA2-256 | A2999 |
| HMAC-SHA2-384 | A2999 |
| HMAC-SHA2-512 | A2999 |
| KAS-ECC-SSC Sp800-56Ar3 | A2999 |
| KDF TLS | A2999 |
| RSA SigGen (FIPS186-4) | A2999 |
| RSA SigVer (FIPS186-4) | A2999 |
| SHA-1 | A2999 |
| SHA2-256 | A2999 |
| SHA2-256 | A3429 |
| SHA2-384 | A2999 |
| SHA2-512 | A2999 |
flowchart LR
%% Deterministic review-risk graph for GlobalProtect App
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>no authentication<br/>Show Status</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for GlobalProtect App
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>no authentication<br/>Show Status</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;GlobalProtect App (Android/iOS/Linux/macOS/Windows) Software Version: 6.0.10 Hardware Version: Intel Core i3-1215U Intel Core i7-1250U Apple M Series M1 Apple A Series A14 Qualcomm Snapdragon 888 Palo Alto Networks, Inc. www.paloaltonetworks.com © 2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies. Revision Date: October 3, 2024 Document Version: 1.20
| # | Section | Page |
|---|
| ISO/IEC24759Section 6.[NumberBelow] | FIPS140-3SectionTitle | SecurityLevel |
|---|---|---|
| 1 | General | 1 |
| 2 | CryptographicModuleSpecification | 1 |
| 3 | CryptographicModuleInterfaces | 1 |
| 4 | Roles,Services,andAuthentication | 1 |
| 5 | Software/FirmwareSecurity | 1 |
| 6 | OperationalEnvironment | 1 |
| 7 | PhysicalSecurity | 1 |
| 8 | Non-InvasiveSecurity | N/A |
| 9 | SensitiveSecurityParameterManagement | 1 |
| 10 | Self-Tests | 1 |
| 11 | Life-CycleAssurance | 3 |
| 12 | MitigationofOtherAttacks | N/A |
| Overall | 1 |
The table below provides the Security Levels of the various sections of FIPS 140-3 in relation to the Palo Alto Networks GlobalProtect App (hereinafter referred to as the Module). ISO/IEC 24759 Section FIPS 140-3 Section Title Security Level 6. [Number Below]
2 Cryptographic Module Specification 1 3 Cryptographic Module Interfaces 1 4 Roles, Services, and Authentication 1 5 Software/Firmware Security 1 6 Operational Environment 1 7 Physical Security 1 8 Non-Invasive Security N/A 9 Sensitive Security Parameter Management 1 11 Life-Cycle Assurance 3 12 Mitigation of Other Attacks N/A
Table 1 - Security Levels
| # | OperatingSystem | HardwarePlatform | Processor | PAA/Acceleration |
|---|---|---|---|---|
| 1 | LinuxUbuntu20.04 | HPPavilion | IntelCorei3-1215U | AES-NI |
| 2 | Windows11 | HPEnvy | IntelCorei7-1250U | AES-NI |
| 3 | macOSBigSur11 | MacBookAir | AppleMSeriesM1 | NEON |
| 4 | iOS16 | iPhone12Mini | AppleASeriesA14 | NEON |
| 5 | Android12 | SamsungGalaxyS21Ultra | QualcommSnapdragon888 | AES-NI |
| # | OperatingSystem | HardwarePlatform |
|---|---|---|
| 1 | Windows11 | ARMDevices |
| 2 | Windows10 | IntelandARMDevices |
| 3 | macOSBigSur,Monterey | IntelDevices |
| 4 | macOSBigSur,Ventura | ARMDevices |
| 5 | RedHat8.1 | GPC |
| 6 | CentOS8.3 | GPC |
| 7 | GoogleAndroid13 | Pixel4andPixel6 |
| 8 | AppleiOS | AppleiPhone |
| CAVP Cert | Algorithmand Standard | Mode/Method | Description/KeySize(s)/ KeyStrength(s) | Use/Function |
|---|---|---|---|---|
| A1362 | CounterDRBG [SP800-90Arev1] | CTRDRBG | AES256bitswithoutDerivation FunctionandwithPrediction ResistanceEnabled | VettedconditionerforESV Cert.#E14 |
| A2873 | ConditioningComponent AES-CBC-MAC [SP800-90B] | AES-CBC-MAC | 128bits | IntelConditionerforEntropy Source |
| A2999 | AES-CBC[SP800-38A] | CBC | 128,192and256bits | Encryption Decryption |
| A2999 | AES-CTR[SP800-38A] | CTR | 128,192and256bits Note:128,192,and256bitswere tested,butnotavailableforuse | Encryption Decryption |
| A2999 | AES-ECB[SP800-38A] | ECB | 128,192and256bits | Encryption Decryption |
| A2999 | AES-GCM [SP800-38D] | GCM | 128and256bits Note:192bitstested,butnot availableforuse | Encryption Decryption |
| A2999 | CounterDRBG [SP800-90Arev1] | CTRDRBG | AES256bitswithDerivation FunctionEnabled | RandomBitGenerator |
| A2999 | ECDSAKeyGen (FIPS186-4) | ECDSAKeyGen | P-256,P-384,P-521 | KeyGeneration |
# Operating System Hardware Platform Processor PAA/Acceleration 1 Linux Ubuntu 20.04 HP Pavilion Intel Core i3-1215U AES-NI 2 Windows 11 HP Envy Intel Core i7-1250U AES-NI 3 macOS Big Sur 11 MacBook Air Apple M Series M1 NEON 4 iOS 16 iPhone 12 Mini Apple A Series A14 NEON 5 Android 12 Samsung Galaxy S21 Ultra Qualcomm Snapdragon 888 AES-NI Table 2 - Tested Operational Environments # Operating System Hardware Platform 1 Windows 11 ARM Devices 2 Windows 10 Intel and ARM Devices 3 macOS Big Sur, Monterey Intel Devices 4 macOS Big Sur, Ventura ARM Devices 5 RedHat 8.1 GPC 6 CentOS 8.3 GPC 7 Google Android 13 Pixel 4 and Pixel 6 8 Apple iOS Apple iPhone Table 2A - Vendor Affirmed Operational Environments The module utilizes the following Approved algorithms that have the following CAVP certificates: Cert Standard Key Strength(s) A1362 AES 256 bits without Derivation Counter DRBG Vetted conditioner for ESV CTR DRBG Function and with Prediction Resistance Enabled A2873 Conditioning Component Intel Conditioner for Entropy [SP 800-90B] Note: 128, 192, and 256 bits were tested, but not available for use [SP 800-38D] Note: 192 bits tested, but not Decryption available for use A2999 Counter DRBG AES 256 bits with Derivation CTR DRBG Random Bit Generator [SP 800-90Arev1] Function Enabled A2999 ECDSA KeyGen Key Generation (FIPS 186-4)
4 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| A2999 | ECDSAKeyVer(FIPS186-4) | ECDSAKeyVer | P-256,P-384,P-521 | PublicKeyValidation |
|---|---|---|---|---|
| A2999 | ECDSASigGen(FIPS186-4) | ECDSASigGen | P-256,P-384,P-521with SHA2-256,SHA2-384,and SHA2-512 | SignatureGeneration |
| A2999 | ECDSASigVer(FIPS186-4) | ECDSASigVer | P-256,P-384,P-521with SHA2-256,SHA2-384,and SHA2-512 | SignatureVerification |
| A2999 | HMAC-SHA-1[FIPS198-1] | HMAC | HMAC-SHA-1withλ=160 | Authenticationforprotocols |
| A2999 | HMAC-SHA2-256 [FIPS198-1] | HMAC | HMAC-SHA2-256withλ=256 | Authenticationforprotocols |
| A2999 | HMAC-SHA2-384 [FIPS198-1] | HMAC | HMAC-SHA2-384withλ=384 | Authenticationforprotocols |
| A2999 | HMAC-SHA2-512 [FIPS198-1] | HMAC | HMAC-SHA2-512withλ=512 Note:Tested,butnotavailableforuse | Authenticationforprotocols |
| A2999 | KAS-ECC-SSCSP800-56Ar3 | SP800-56Arev3.KAS-ECC perIGD.FScenario2path (2) | EphemeralUnifiedschemeusing P-256/P-384/P-521providing 128/192/256bitsofstrength | KeyExchange |
| A2999 | KDFTLS [SP800-135rev1](CVL) | TLS1.2KDF | TLSv1.2HashAlgorithm: SHA2-256,SHA2-384 | TLS |
| A2999 | RSA SigGen (FIPS186-4) | RSA SigGen (FIPS186-4) | PKCS#1v1.5:2048,3072,and 4096-bitwithhashes SHA2-256/384/512 | SignatureGeneration |
| A2999 | RSA SigVer (FIPS186-4) | RSA SigVer (FIPS186-4) | PKCS#1v1.5: 2048,3072, 4096-bit(perIGC.F)withhashes SHA2-256,SHA2-384, SHA2-512(SignatureVerification) | SignatureVerification |
| A2999 | SHA-1[FIPS180-4] | SHA | SHA-1 | Non-DigitalSignature Applications(e.g.componentof HMAC) |
| A2999 | SHA2-256[FIPS180-4] | SHA2 | SHA2-256 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g.componentof HMAC) |
| A2999 | SHA2-384[FIPS180-4] | SHA2 | SHA2-384 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g.componentof HMAC) |
| A2999 | SHA2-512[FIPS180-4] | SHA2 | SHA2-512 | DigitalSignature Generation/Verification Non-DigitalSignature Applications(e.g.componentof HMAC) |
| A3429 | SHA2-256[FIPS180-4] | SHA2 | SHA2-256 | VettedconditionerforESV Cert.#E15 |
| AES Cert. A2999 | KTS [SP800-38F] | SP800-38A,FIPS198-1, andSP800-38F.KTS(key | AES-CBCplusHMAC | KeyWrapping |
A2999 Public Key Validation ECDSA KeyVer (FIPS 186-4) ECDSA KeyVer P-256, P-384, P-521 Signature Generation A2999 HMAC-SHA-1 [FIPS 198-1] HMAC HMAC-SHA-1 with λ=160 Authentication for protocols HMAC HMAC-SHA2-256 with λ=256 Authentication for protocols [FIPS 198-1] HMAC HMAC-SHA2-384 with λ=384 Authentication for protocols [FIPS 198-1] HMAC Authentication for protocols [FIPS 198-1] Note: Tested, but not available for use A2999 SP 800-56Arev3. KAS-ECC EphemeralUnified scheme using per IG D.F Scenario 2 path P-256/P-384/P-521 providing KAS-ECC-SSC SP 800-56Ar3 Key Exchange (2) 128/192/256 bits of strength A2999 KDF TLS TLS 1.2 KDF TLS v1.2 Hash Algorithm: 4096-bit with hashes (FIPS 186-4) (FIPS 186-4) 4096-bit (per IG C.F) with hashes (FIPS 186-4) (FIPS 186-4) A2999 Non-Digital Signature SHA-1 [FIPS 180-4] SHA Applications (e.g. component of A2999 Digital Signature SHA2-256 [FIPS 180-4] SHA2 SHA2-256 Non-Digital Signature Applications (e.g. component of A2999 Digital Signature SHA2-384 [FIPS 180-4] SHA2 SHA2-384 Non-Digital Signature Applications (e.g. component of A2999 Digital Signature SHA2-512 [FIPS 180-4] SHA2 SHA2-512 Non-Digital Signature Applications (e.g. component of A3429 Vetted conditioner for ESV SHA2-256 [FIPS 180-4] SHA2 SHA2-256 KTS SP 800-38A, FIPS 198-1, Cert. AES-CBC plus HMAC Key Wrapping © 2024 Palo Alto Networks, Inc. Palo Alto Networks GlobalProtect App 5 This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| and HMAC Cert. A2999 | wrappingandunwrapping) perIGD.G. | 128,192,and256-bitkeys providing128,192,or256bitsof encryptionstrength | ||
|---|---|---|---|---|
| AES-GC MCert. A2999 | KTS [SP800-38F] | SP800-38DandSP 800-38F.KTS(keywrapping andunwrapping)perIGD.G. | AES-GCM 128and256-bitkeysproviding128 or256bitsofencryptionstrength | KeyWrapping |
| ESV Cert. #E14 | ESV[SP800-90B] | ESV | Applecorecryptophysicalentropy source | Entropy |
| ESV Cert. #E15 | ESV[SP800-90B] | ESV | Applecorecryptonon-physical entropysource | Entropy |
| KAS-EC C-SSC Cert. #A2999, KDFTLS Cert. #A2999 | KAS[SP800-56Arev3] | SP800-56Arev3.KAS-ECC perIGD.FScenario2path (2). | P-256,P-384,andP-521curves providing128,192,or256bitsof encryptionstrength | KeyExchangewithprotocol KDF |
| N/A | ENT(P)(SP800-90B) | ENT | ENT(P) | Entropy |
| Vendor Affirmed | CKG (SP800-133rev2) | Section5.2 | CryptographicKey Generation;SP800- 133andIGD.H. | KeyGeneration Note:Theseedsusedfor asymmetrickeypairgeneration areproducedusingthe unmodified/directoutputofthe DRBG |
and wrapping and unwrapping) 128, 192, and 256-bit keys HMAC per IG D.G. providing 128, 192, or 256 bits of Cert. encryption strength M Cert. 800-38F. KTS (key wrapping 128 and 256-bit keys providing 128 Key Wrapping A2999 and unwrapping) per IG D.G. or 256 bits of encryption strength Apple corecrypto physical entropy Apple corecrypto non-physical Key Exchange with protocol #A2999, KAS [SP 800-56Arev3] per IG D.F Scenario 2 path providing 128, 192, or 256 bits of KDF TLS (2). encryption strength Key Generation Note: The seeds used for Cryptographic Key Vendor CKG asymmetric key pair generation Section 5.2 Generation; SP 800Affirmed (SP 800-133rev2) are produced using the
unmodified/direct output of the Table 3 - Approved Algorithms Notes:
6 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
Cryptographic Boundary Figure 1 below depicts the cryptographic boundary and physical perimeter (light blue color area). The cryptographic boundary includes all of the software components and the specified hardware components (CPU’s). The physical perimeter is the Tested Operational Environment’s Physical Perimeter (TOEPP) on which the module runs. Figure 1: Cryptographic Boundary * See details below regarding Operating Systems/Environments tested Figure 1B: Hardware Components © 2024 Palo Alto Networks, Inc. Palo Alto Networks GlobalProtect App 7 This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| PhysicalPort | LogicalInterface | Datathatpassesoverport/interface |
|---|---|---|
| Physicalportsofthetestedplatform | StatusOutput | GUIstatuswindowandlogfilesgeneratedand outputviaGUI/CLI |
| Physicalportsofthetestedplatform | DataInput | Portalinformation,keysfromOScertificatestore orduringTLS/IPsecnegotiation |
| Physicalportsofthetestedplatform | DataOutput | KeysforestablishingsecuresessionssuchasTLS |
| Physicalportsofthetestedplatform | ControlInput | GUI/CLI,stringvaluefrompangps.xml, com.paloaltonetworks.gp.pangps.plist, MDM,or WindowsRegistry(SeeSecureOperationsection below) |
| Role | Service | Input | Output |
|---|---|---|---|
| Crypto-Officer | ShowStatus | Requestsystemstatus | Moduledisplaysstatusinformation |
| ShowVersion | Querymoduleforversion information | Moduledisplaysversioninformation | |
| Self-Test | Commandmoduletorun Self-Tests | ModuleprovidesoutputofSelf-Testresults vialogs |
8 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| Security Configuration Management | Configuringmodulewith setupdatadetailstosupport VPNestablishment | Logsprovideconfigurationchanges |
|---|---|---|
| VPNTunnel | InitializeVPNconnection | SystemlogprovideVPNstatus |
| Zeroize | Commandmoduletozeroize | AllSSPszeroized(moduleuninstalled) |
| Service | Description | Approved Security Functions | Keysand/orSSPs | Roles | Accessrights toKeys and/orSSPs | Indicator | |
|---|---|---|---|---|---|---|---|
| ShowStatus | Provides information regardingthe statusofthe system(fetched viaGUI/CLI) | N/A | N/A | Crypto-Officer | N/A | Systemlogsor statuswindow | |
| ShowVersion | Provides information regardingversion | N/A | N/A | Crypto-Officer | N/A | Module provides version information | |
| Self-Test | Performs on-demand Self-Tests (executedvia rebootof platform) | RSASigVer(FIPS 186-4) | SoftwareIntegrity VerificationKey | Crypto-Officer | E | Systemlogs | |
| Security Configuration Management | Configuresthe modulewith necessarysetup detailstosupport VPN establishment (updatedvia GUI/CLI) | N/A | CACertificates RSAPublicKeys RSAPrivateKeys ECDSAPublicKeys ECDSAPrivateKeys | Crypto-Officer | R/W/E | Systemlogs | |
| VPNTunnel | Createsan SSL/IPsecVPN tunnel(executed byoperator interactionwith GUI/CLI) | KAS | KDFTLS | TLSPre-MasterSecret | Crypto-Officer | G/E/Z | Systemlogs |
| KDFTLS | TLSMasterSecret | G/E/Z | |||||
| CKG, ECDSA KeyGen(FIPS 186-4),ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC | TLSECDHEPublic Components | G/E/Z | |||||
| TLSECDHEPrivate Components | G/E/Z | ||||||
| KTS | HMAC-SHA2- 256 HMAC-SHA2- 384 | TLSHMACKeys | G/E/Z | ||||
| AES-CBC | TLSEncryptionKeys | ||||||
| KTS | AES-GCM | ||||||
| RSASigVer(FIPS 186-4) | CACertificates | W/E |
Security Configuring module with Logs provide configuration changes Configuration setup data details to support VPN Tunnel Initialize VPN connection System log provide VPN status Zeroize Command module to zeroize All SSPs zeroized (module uninstalled) Table 5 - Roles, Service Commands, Input and Output Service Description Approved Keys and/or SSPs Roles Access rights Indicator Security to Keys Functions and/or SSPs Show Status Provides N/A N/A Crypto-Officer N/A System logs or information status window regarding the status of the regarding version version Self-Test Performs RSA SigVer (FIPS Software Integrity Crypto-Officer E System logs (executed via reboot of Security Configures the N/A CA Certificates Crypto-Officer R/W/E System logs Configuration module with RSA Public Keys Management necessary setup RSA Private Keys details to support ECDSA Public Keys VPN ECDSA Private Keys (updated via VPN Tunnel Creates an KAS KDF TLS TLS Pre-Master Secret Crypto-Officer G/E/Z System logs SSL/IPsec VPN KDF TLS TLS Master Secret G/E/Z tunnel (executed CKG, TLS ECDHE Public G/E/Z by operator ECDSA Components interaction with KeyGen (FIPS TLS ECDHE Private G/E/Z AES-CBC TLS Encryption Keys CA Certificates W/E RSA SigVer (FIPS © 2024 Palo Alto Networks, Inc. Palo Alto Networks GlobalProtect App 9 This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| ECDSASigVer(FIPS 186-4) | ||||||
|---|---|---|---|---|---|---|
| RSASigVer(FIPS 186-4) | RSAPublicKeys | W/E | ||||
| RSASigGen(FIPS 186-4) | RSAPrivateKeys | E | ||||
| ECDSASigVer(FIPS 186-4) | ECDSAPublicKeys | W/E | ||||
| ECDSASigGen(FIPS 186-4) | ECDSAPrivateKeys | E | ||||
| AES-CBC AES-GCM | IPSecSessionKeys | W/E | ||||
| HMAC-SHA-1 | IPSecAuthentication Keys | W/E | ||||
| CounterDRBG, ENT(P),ESV | EntropyInputString, DRBGSeed | G/E/Z | ||||
| CounterDRBG | DRBGKey | G/E/Z | ||||
| DRBGV | G/E/Z | |||||
| Zeroize | RemovesallSSPs fromthemodule (Performedvia uninstallofthe module) | N/A | AllKeysandSSPs | Crypto-Officer | Z | Removalof moduleand confirmation viaOSstatus window |
ECDSA SigVer (FIPS RSA SigVer (FIPS RSA Public Keys W/E RSA SigGen (FIPS RSA Private Keys E ECDSA SigVer (FIPS ECDSA Public Keys W/E ECDSA SigGen (FIPS ECDSA Private Keys E HMAC-SHA-1 IPSec Authentication W/E Counter DRBG, Entropy Input String, G/E/Z ENT (P), ESV DRBG Seed Counter DRBG DRBG Key G/E/Z DRBG V G/E/Z Zeroize Removes all SSPs N/A All Keys and SSPs Crypto-Officer Z Removal of from the module module and (Performed via confirmation uninstall of the via OS status Table 6 - Approved Services G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Note: There is no table for non-Approved services as the module only supports Approved services. 5. Software/Firmware Security The module performs the Software Integrity test by verifying the digital signature of the module using RSA 2048 with SHA2-256 (Cert. #A2999) or RSA 3072 with SHA2-384 (Cert. #A2999) during the Pre-Operational Self-Test. RSA 2048 with SHA2-256 is used for Windows/macOS/iOS/Android (OE #2, 3, 4, 5 in Table 2) and RSA 3072 with SHA2-384 is used for Linux (OE #1 in Table 2). The Software Integrity Verification Key is used for this integrity test. The integrity test can be performed by restarting the GlobalProtect app service, which is noted in the Life-Cycle Assurance section for each platform. The test can also be performed by restarting the platform for which the module runs on. Either of the actions (restarting the GlobalProtect app service or restarting the host platform) can be used to perform the integrity test on demand. For information regarding the file type, see details in Operational Environment. The module comes packaged and ready for installation once it has been downloaded from the Palo Alto Networks support site.
10 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| Platform | PackageName |
|---|---|
| Linux | PanGPLinux-6.0.10.tgz |
| Windows | GlobalProtect64-6.0.10.msi |
| macOS | GlobalProtect-6.0.10.pkg |
| iOS | 6.0.10onAppStore |
| Android | 6.0.10onGooglePlay |
| Key/SSP Name/Type | Strength | Security Functionand Cert.Number | Generation | Import/Export1 | Establishment | Storage2,3 | Zeroization4 | Use&RelatedKeys |
|---|---|---|---|---|---|---|---|---|
| CACertificates | 112-256 bits | RSASigVer (FIPS186-4), ECDSASigVer (FIPS186-4) Cert.#A2999 | N/A | Import/Exporte dinplaintext | N/A | Protectedin OSkeystore | Zeroization service | ECDSA/RSAPublickey usedtoextendtrusttoa rootCA,intermediateCA, andleft/endentity certificates |
| RSAPublic Keys | 112-150 bits | RSASigVer (FIPS186-4) Cert.#A2999 | N/A | Import:Yes fromOSkey storeor Plaintextduring TLShandshake Export: Plaintextduring TLShandshake | N/A | Protectedin OSkeystore | Zeroization service | RSApublickeysmanaged ascertificatesforthe verificationofsignatures, establishmentofTLS,and peerauthentication.(RSA 2048/3072/4096bits) |
| RSAPrivate Keys | 112-150 bits | RSASigGen (FIPS186-4) Cert.#A2999 | N/A | Imported: Encryptedvia TLS Exported:No | N/A | Protectedin OSkeystore | Zeroization service | RSAPrivatekeyusedfor authentication,and signaturegeneration (RSA2048,3072,or4096 bits). |
| ECDSAPublic Keys | 128-256 bits | ECDSASigVer (FIPS186-4) Cert.#A2999 | N/A | Import:Yes fromOSkey storeor Plaintextduring TLShandshake Export: Plaintextduring TLShandshake | N/A | Protectedin OSkeystore | Zeroization service | ECDSApublickeys managedascertificates fortheverificationof signatures,establishment ofTLS,andpeer authentication. (P-256/384/521) |
| ECDSAPrivate Keys | 128-256 bits | ECDSA SigGen(FIPS 186-4) Cert.#A2999 | N/A | Imported: Encryptedvia TLS Exported:No | N/A | Protectedin OSkeystore | Zeroization service | ECDSAPrivatekeyused forauthentication,and signaturegeneration (P-256,P-384orP-521. |
| TLSECDHE Private Components | 128-256 bits | ECDSA KeyGen(FIPS 186-4), ECDSA KeyVer(FIPS 186-4), KAS-ECC-SSC Cert.#A2999 | CKG | N/A | N/A | RAM– Plaintext | Zeroizedat session termination | ECDHEprivate componentusedinkey agreement (P-256,P-384,P-521) |
| TLSECDHE Public Components | 128-256 bits | KAS-ECC-SSC Cert.#A2999 | N/A | Import:No Export:Only exitsthemodule tothepeerfor TLSprotocol implementation | N/A | RAM– Plaintext | Zeroizedat session termination | ECDHEpubliccomponent usedinkeyagreement (P-256/384/521) |
| TLS Pre-Master Secret | N/A | KDFTLS Cert.#A2999 | N/A | N/A | KAS | RAM– Plaintext | Zeroizedat session termination | ValueusedduringTLS handshakeforsession negotiation |
| TLSMaster Secret | N/A | KDFTLS Cert.#A2999 | N/A | N/A | Derivedusing SP800-135 KDF | RAM– Plaintext | Zeroizedat session termination | Secretvalueusedto derivetheTLSsessionkey |
| TLSEncryption Keys | 128or 256bits | AES-CBC, AES-GCM Cert.#A2999 | N/A | N/A | Derivedusing SP800-135 KDF | RAM– Plaintext | Zeroizedat session termination | AESkeysusedinTLS connections (AES128/256bitsGCM orCBC) |
RSA SigVer used to extend trust to a CA Certificates N/A N/A root CA, intermediate CA, and left/end entity from OS key RSA public keys managed store or as certificates for the RSA SigVer RSA Public 112 - 150 Plaintext during Protected in Zeroization verification of signatures, TLS handshake RSA Private 112 - 150 Encrypted via Protected in Zeroization from OS key managed as certificates store or ECDSA SigVer for the verification of Plaintext during TLS handshake N/A N/A TLS ECDHE Zeroized at TLS ECDHE exits the module Zeroized at ECDHE public component bits Cert. #A2999 to the peer for Plaintext TLS protocol TLS Zeroized at Value used during TLS Derived using Zeroized at N/A N/A N/A SP 800-135 session 128 or AES-CBC, Derived using Zeroized at
or CBC) All SSPs are electronically imported/exported. At first load, the CA Certificates, RSA/ECDSA Public Keys are manually imported. For items noted as protected by OS key store, this refers to the platform on which the module is installed providing a space to host these keys/SSPs and utilizing control mechanisms to ensure only proper individuals can access these items (e.g. operator must authenticate to GPC to access them). The GPC also provides security as the key store is protected in the physical perimeter of the GPC. These keys are considered to be outside the module’s cryptographic boundary. The module does not provide persistent keys/SSPs storage. Zeroization service is an explicit service unless it is handling temporary values, which are zeroized implicitly upon session termination or when the platform is rebooted. When the zeroization service is invoked, it overwrites files with a random pattern.
12 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| TLSHMAC Keys | 256-384 bits | HMAC-SHA2- 256, HMAC-SHA2- 384 Cert.#A2999 | N/A | NA | Derivedusing SP800-135 KDF | RAM– Plaintext | Zeroizedat session termination | HMACkeysusedinTLS connections (SHA2-256,SHA2-384) |
|---|---|---|---|---|---|---|---|---|
| IPSecSession Keys | 128bits minimum | AES-CBC, AES-GCM Cert.#A2999 | N/A | Imported Encryptedvia AES-GCM/CBC | KTS | RAM– Plaintext | Zeroizedat session termination | Usedtoencryptsessions AESCBC(128bits)orAES GCM(128or256bits) |
| IPSec Authentication Key | 160bits | HMAC-SHA-1 Cert.#A2999 | N/A | Imported Encryptedvia AES-GCM/CBC | KTS | RAM– Plaintext | Zeroizedat session termination | Usedaspartof authenticationforIPsec data(HMAC-SHA-1) |
| EntropyInput String | 112bits minimum | CKG(vendor affirmed), ENT(P), ESV, Counter DRBG Cert.#A2999 | Entropyas perSP 800-90B | N/A | N/A | RAM-plaintext | Powercycle | DRBGentropyinput stringcomingfromthe entropysourceusedin thegenerationofrandom values |
| DRBGSeed | 384bits | Counter DRBG Cert.#A2999 | Entropyas perSP 800-90B | N/A | N/A | RAM-plaintext | Powercycle | DRBGseedcomingfrom theentropyinputstring usedinthegenerationof randomvalues |
| DRBGKey | 256bits | Counter DRBG Cert.#A2999 | Constructe dasper SP-800-90 Ar1 | N/A | N/A | RAM-plaintext | Powercycle | InternalDRBGState |
| DRBGV | 128bits | Counter DRBGCert. #A2999 | Constructe dasperSP 800-90Ar1 | N/A | N/A | RAM-plaintext | Powercycle | InternalDRBGState |
| Software Integrity Verification Key | 2048or 3072bits | RSASigVer (FIPS186-4) Cert.#A2999 | N/A | N/A | Pre-computed atcompile time | RAM-plaintext | Zeroization service | Usedtoverifythe integrityofthemodule (Note:Thisisnotconsidered anSSP) |
256, Derived using Zeroized at HMAC keys used in TLS AES-CBC, Imported Zeroized at Used to encrypt sessions IPSec Imported Zeroized at Used as part of Authentication 160 bits N/A Encrypted via KTS session authentication for IPsec affirmed), DRBG entropy input ENT (P), Entropy as string coming from the Entropy Input 112 bits ESV, per SP N/A N/A RAM - plaintext Power cycle entropy source used in Counter 800-90B the generation of random DRBG seed coming from Counter Entropy as the entropy input string used in the generation of random values d as per DRBG V 128 bits DRBG Cert. d as per SP N/A N/A RAM - plaintext Power cycle Internal DRBG State Software Used to verify the RSA SigVer Pre-computed Integrity 2048 or Zeroization integrity of the module (FIPS 186-4) N/A N/A at compile RAM - plaintext Verification 3072 bits service (Note: This is not considered Key an SSP) Table 8 - SSPs © 2024 Palo Alto Networks, Inc. Palo Alto Networks GlobalProtect App 13 This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| EntropySources | MinimumNumberofBitsof Entropy | Details |
|---|---|---|
| AppleNon-PhysicalEntropy Source | 384bits | ThemoduleusesentropyprovidedbyApple’sentropysource,whichis coveredbyESVcert.#E15.Thisentropysourceprovidesfullentropyper output.TheDRBGisseededwith384bitsofentropyfromthissource. (AppleASeriesprocessor) |
| ApplePhysicalEntropy Source | 384bits | ThemoduleusesentropyprovidedbyApple’sentropysource,whichis coveredbyESVcert.#E14.Thisentropysourceprovidesfullentropyper output.TheDRBGisseededwith384bitsofentropyfromthissource. (AppleMSeriesprocessor) |
| IntelRDSEED | 384bits | EntropyprovidedbyIntelCPUwithRDSEEDasthenoisesourcetoprovide atleast384bitsofentropytoseedtheDRBG.Thisentropysourceprovides fullentropyperoutput.TheDRBGisseededwith384bitsofentropyfrom thissource.(WindowsandLinuxplatforms) |
| N/A | 112bits | ForAndroidplatforms,themoduleperformsanentropyloadthatmeets FIPS140-3IG9.3.AScenario2(b). TheDRBGisseededwith384bitsofdata whichisassumedtocontainatleast112bitsofentropy. NoassuranceoftheminimumstrengthofgeneratedSSPs(e.g.,keys) |
| Algorithm | Self-TestDetails |
|---|---|
| Software IntegrityTest | Digitalsignatureverification(PKCS#1v1.5)usingRSA2048bitswithSHA2-256orRSA3072 bitswithSHA2-384(Linux) Note:TheRSAandSHA2-256/SHA2-384CASTsareperformedpriortotheSoftwareIntegrity Test. |
| Algorithm | Self-TestDetails |
|---|---|
| AESECBEncrypt | KATusingAESECB128bits |
| AESECBDecrypt | KATusingAESECB128bit |
| AESGCMEncrypt | KATusingAESGCM256bits |
| AESGCMDecrypt | KATusingAESGCM256bits |
| CounterDRBG | KAT:AES-256CounterDRBG Note: DRBGHealthTestsasspecifiedinSP800-90ASection11.3areperformed (i.e.instantiate/generate/reseed) |
Entropy Sources Minimum Number of Bits of Details Apple Non-Physical Entropy 384 bits The module uses entropy provided by Apple’s entropy source, which is Source covered by ESV cert. #E15. This entropy source provides full entropy per output. The DRBG is seeded with 384 bits of entropy from this source. (Apple A Series processor) Apple Physical Entropy 384 bits The module uses entropy provided by Apple’s entropy source, which is Source covered by ESV cert. #E14. This entropy source provides full entropy per output. The DRBG is seeded with 384 bits of entropy from this source. (Apple M Series processor) Intel RDSEED 384 bits Entropy provided by Intel CPU with RDSEED as the noise source to provide at least 384 bits of entropy to seed the DRBG. This entropy source provides full entropy per output. The DRBG is seeded with 384 bits of entropy from this source. (Windows and Linux platforms) N/A 112 bits For Android platforms, the module performs an entropy load that meets FIPS 140-3 IG 9.3.A Scenario 2(b). The DRBG is seeded with 384 bits of data which is assumed to contain at least 112 bits of entropy. No assurance of the minimum strength of generated SSPs (e.g., keys) Table 9 - Non-Deterministic Random Number Generation Specification 10. Self-Tests The cryptographic module performs the following tests below. The operator can command the module to perform the pre-operational and cryptographic algorithm self-tests (CASTs) by reloading the module or power cycling the underlying platform; these tests do not require any additional operator action. In the event that a Self-Test fails, the module will enter an error state until the issue is resolved, and provide a status output message with the failure. Pre-Operational Self-Tests Software Digital signature verification (PKCS #1 v1.5) using RSA 2048 bits with SHA2-256 or RSA 3072 Integrity Test bits with SHA2-384 (Linux) Note: The RSA and SHA2-256/SHA2-384 CASTs are performed prior to the Software Integrity Table 10 - Pre-Operational Self-Tests Conditional Self-Tests AES ECB Encrypt KAT using AES ECB 128 bits AES ECB Decrypt KAT using AES ECB 128 bit AES GCM Encrypt KAT using AES GCM 256 bits AES GCM Decrypt KAT using AES GCM 256 bits Note: DRBG Health Tests as specified in SP800-90A Section 11.3 are performed
14 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
| ECDSASign | KATusingP-256andSHA2-256 |
|---|---|
| ECDSAVerify | KATusingP-256andSHA2-256 |
| HMAC-SHA-1 | KATusingHMAC-SHA-1 |
| HMAC-SHA2-224 | KATusingHMAC-SHA2-224 Note:Onlyusedforself-test. |
| HMAC-SHA2-256 | KATusingHMAC-SHA2-256 |
| HMAC-SHA2-384 | KATusingHMAC-SHA2-384 |
| HMAC-SHA2-512 | KATusingHMAC-SHA2-512 |
| RSASign | KATusingRSA2048bitsandSHA2-256(PKCS#1v1.5andPKCSPSS) |
| RSAVerify | KATusingRSA2048bitsandSHA2-256(PKCS#1v1.5andPKCSPSS) |
| SHA-1 | KATusingSHA-1 |
| SHA2-256 | KATusingSHA2-256 |
| SHA2-384 | KATusingSHA2-384 |
| SHA2-512 | KATusingSHA2-512 |
| SP800-56Ar3KAS-ECC-SSC | KATforKAS-ECC-SSCusingP-256(SharedSecretComputation)primitiveZvalue |
| SP800-135r1KDFTLS | KATforTLSv1.2KDF |
| SP800-90BHealthTests | SP800-90BHealthTestsontheEntropySource |
| Algorithm | Self-TestDetails |
|---|---|
| ECC | ECCPair-wiseConsistencyTest(PCT)forECDSAandKAS-ECCkeypairs |
| Algorithm | Self-TestDetails |
|---|---|
| SP800-56Arev3 KAS-ECC-SSC | SP800-56Arev3AssuranceTestsbasedonSections5.5.2,5.6.2,and5.6.3 |
| Error | StatusIndicator |
|---|---|
| ConditionalCryptographicAlgorithmSelf-TestFailure | Systemprintslogwitherrormessage |
| IntegrityTestFailure | Systemprintslogwitherrormessage |
| ConditionalTestFailure | Systemprintslogwitherrormessage |
ECDSA Sign KAT using P-256 and SHA2-256 ECDSA Verify KAT using P-256 and SHA2-256 HMAC-SHA-1 KAT using HMAC-SHA-1 Note: Only used for self-test. RSA Sign KAT using RSA 2048 bits and SHA2-256 (PKCS #1 v1.5 and PKCS PSS) RSA Verify KAT using RSA 2048 bits and SHA2-256 (PKCS #1 v1.5 and PKCS PSS) SHA-1 KAT using SHA-1 SHA2-256 KAT using SHA2-256 SHA2-384 KAT using SHA2-384 SHA2-512 KAT using SHA2-512 SP 800-56Ar3 KAS-ECC-SSC KAT for KAS-ECC-SSC using P-256 (Shared Secret Computation) primitive Z value SP 800-135r1 KDF TLS KAT for TLSv1.2 KDF SP 800-90B Health Tests SP 800-90B Health Tests on the Entropy Source Table 11
Secure Delivery Procedures The security of the module is maintained during the transfer of these products from production sites to the customer through the following mechanisms:
16 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)
○ HKEY_LOCAL_MACHINES\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\
○ Restart the GlobalProtect App application and GlobalProtect App service (PanGPS) ■ Launch Terminal ■ Execute the following commands: username>$ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist username>$ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangps.plist username>$ launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangps.plist username>$ launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist iOS For the GlobalProtect App running on iOS, complete the steps below: ● Access the App Store on the Apple device ● Search for GlobalProtect and download the application ● Once the app has been downloaded, navigate to the MDM to initialize the Approved state (“FIPS-CC mode”) on the endpoint ● On the MDM service such as Workspace One, enter the following custom key: ○ Key: enable-fips-cc-mode ○ Value: yes ● Push the configuration to the iOS device, and then restart the application Android To initialize the GP App into its Approved state (“FIPS-CC mode”), follow the procedure below: ● Access the Google Play store ● Search for GlobalProtect and download the application ● Once the app has been downloaded, navigate to the MDM to initialize the Approved state (FIPS-CC mode) on the endpoint ● On the MDM service such as Workspace One, enter the following custom key: ○ Key: enable-fips-cc-mode ○ Value: yes ● Push the configuration to the Android device, and then restart the application End of Life / Sanitization End of life dates for software modules are announced publicly via Palo Alto Networks’ services website. Crypto-Officers shall follow the procedure below for the secure destruction of their module: Note: This process will cause the module to no longer function after it has wiped all configurations and keys. Linux
18 Palo Alto Networks GlobalProtect App © 2024 Palo Alto Networks, Inc.
This Security Policy is non-proprietary and may be reproduced only in its entirety (without revision)