Cryptographic Module Validation Program CMVP

Certificate #3115

Details

Module Name
Panorama M-100 and M-500
Standard
FIPS 140-2
Status
Active
Sunset Date
1/30/2023
Validation Dates
01/31/2018;05/18/2018;10/31/2018;02/21/2020
Overall Level
2
Caveat
When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy
Security Level Exceptions
  • Cryptographic Module Specification: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
Panorama on the M-100 and M-500 provides centralized management and visibility of multiple Palo Alto Networks next-generation firewalls and supports distributed management and logging functions. It allows you to oversee all applications, users, and content traversing the network and then create application enablement policies that protect and control the entire network. The M-500 provides an additional service, the PAN-DB private cloud, which is an on-premise solution suitable for organizations that prohibit or restrict the use of the PAN-DB public cloud service.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Cert. #4532
CKG vendor affirmed
CVL Certs. #1211, #1212, #1213 and #1214
DRBG Cert. #1489
DSA Cert. #1207
ECDSA Cert. #1103
HMAC Cert. #2990
KAS SP 80056Arev2 with CVL Certs. #1211 and #1212, vendor affirmed
KTS AES Cert. #4532; key establishment methodology provides between 128 and 256 bits of encryption strength
KTS AES Cert. #4532 and HMAC Cert. #2990; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Cert. #2467
SHS Certs. #3713
Allowed Algorithms
Diffie-Hellman (CVL Cert. #1211 with CVL Cert. #1212, key agreement; key establishment methodology provides 112 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Hardware Versions
P/Ns 910-000030 Version 00D [1], 910-000092 Version 00D [1] and 910-000073 Version 00D [2]; FIPS Kit P/N 920-000140 Version 00A [1] and FIPS Kit P/N 920-000145 Version 00A [2]
Firmware Versions
8.0.3, 8.0.9, 8.0.12 or 8.0.13

Vendor

Palo Alto Networks
3000 Tannery Way
Santa Clara, CA 95054
USA

Jake Bajic
certifications@paloaltonetworks.com
Phone: 408-753-4000

Lab

UL VERIFICATION SERVICES INC
NVLAP Code: 100432-0