U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

Cryptographic Module Validation Program CMVP

Certificate #3896

Details

Module Name
Panorama 9.0 M-100, M-200, M-500 and M-600
Standard
FIPS 140-2
Status
Active
Sunset Date
4/14/2026
Overall Level
2
Caveat
When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy
Security Level Exceptions
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
Panorama 9.0 on the M-100, M-200, M-500 and M-600 provides centralized management and visibility of multiple Palo Alto Networks next-generation firewalls and supports distributed management and logging functions. It allows you to oversee all applications, users, and content traversing the network and then create application enablement policies that protect and control the entire network. The M-500 and M-600 provide an additional service, the PAN-DB private cloud, which is an on-premise solution suitable for organizations that prohibit or restrict the use of the PAN-DB public cloud service.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Cert. #C1005
CKG vendor affirmed
CVL Cert. #C1005
DRBG Cert. #C1005
DSA Cert. #C1005
ECDSA Cert. #C1005
HMAC Cert. #C1005
KAS KAS-SSC Cert. #A2670 and CVL Cert. #C1005
KAS-SSC Cert. #A2670
KTS AES Cert. #C1005 and HMAC Cert. #C1005; key establishment methodology provides between 128 and 256 bits of encryption strength
KTS AES Cert. #C1005; key establishment methodology provides 128 or 256 bits of encryption strength
RSA Cert. #C1005
SHS Cert. #C1005
Allowed Algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Hardware Versions
P/Ns 910-000030 Version 00D [1], 910-000092 Version 00D [1], 910-000176 Version 00A [2], 910-000073 Version 00D [3], and 910-000175 Version 00A [4]; FIPS Kit P/Ns 920-000140 Version 00A [1], 920-000208 Version 00A [2], 920-000145 Version 00A [3], and 920-000209 Version 00A [4]
Firmware Versions
9.0.9

Vendor

Palo Alto Networks, Inc.
3000 Tannery Way
Santa Clara, CA 95054
USA

Quang Trinh
qtrinh@paloaltonetworks.com
Phone: 669-209-6377
Jake Bajic
jbajic@paloaltonetworks.com
Phone: 408-753-4000

Validation History

Date Type Lab
4/15/2021 Initial UL VERIFICATION SERVICES INC
7/5/2022 Update LEIDOS CSTL