{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "044c06ac12dc9063", "cert_id": 5352, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Panorama 11.1/11.2 running on M-200, M-300, M-600 and M-700", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-06-25", "validation_type": "Initial", "lab": "Leidos Accredited Testing & Evaluation (AT&E) Lab"}], "vendor_url": "http://www.paloaltonetworks.com", "vendor": "Palo Alto Networks, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2026_080726_0648.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy", "exceptions": ["Roles, services, and authentication: Level 3", "Operational environment: N/A", "Non-invasive security: N/A", "Life-cycle assurance: Level 3", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The Panorama M-200, M-300, M-600 and M-700 from Palo Alto Networks Inc., hereafter referred to as \"Panorama M-Series\", \"Panorama HW\", \"modules\", or the \"cryptographic modules\" are multi-chip standalone cryptographic modules designed to fulfill FIPS 140-3 level 2 requirements. Panorama M-Series management appliances provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-06-24", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#14": 2, "#15": 2, "#13": 2, "#18": 2, "#19": 2, "#11": 2, "#12": 2}}, "fips_security_level": {"Level": {"level 2": 1, "Level 1": 1, "Level 2": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 4, "HMAC-SHA-256": 6, "HMAC- SHA-256": 1, "HMAC- SHA-1": 2, "SHA2-224": 3, "SHA2-256": 10, "SHA2-384": 5, "SHA2-512": 6, "SHA-1": 9, "SHA-256": 11, "SHA- 256": 1, "SHA2- 224": 1, "SHA2- 256": 2, "SHA2- 384": 2, "SHA2- 512": 2, "RSA 2048": 11, "RSA 3072": 1, "RSA 4096": 1, "PKCS 1": 4, "AES-256": 3, "AES-128": 1, "AES-192": 1, "AES 256": 2, "AES 128/192/256": 1, "AES (128": 1, "DRBG 2": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 3, "AES-128": 1, "AES-192": 1, "AES": 41, "AES-": 17}, "CAST": {"CAST": 52}}, "constructions": {"MAC": {"HMAC": 41, "HMAC-SHA-256": 3, "CBC-MAC": 3}}}, "asymmetric_crypto": {"RSA": {"RSA 2048": 11, "RSA 3072": 1, "RSA 4096": 1}, "ECC": {"ECDH": {"ECDH": 6, "ECDHE": 2}, "ECDSA": {"ECDSA": 74}, "ECC": {"ECC": 15}}, "FF": {"DH": {"DH": 2, "DHE": 2}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 9}, "SHA2": {"SHA-256": 11}}}, "crypto_scheme": {"MAC": {"MAC": 3}, "KA": {"Key Agreement": 4}}, "crypto_protocol": {"SSH": {"SSH": 103, "SSHv2": 57}, "TLS": {"TLS": {"TLS v1.2": 8, "TLSv1.2": 73, "TLS": 89, "TLS 1.2": 3, "TLSv1.3": 1}}, "IKE": {"IKEv2": 3}, "VPN": {"VPN": 8}}, "randomness": {"PRNG": {"DRBG": 59}, "RNG": {"RBG": 2}}, "cipher_mode": {"ECB": {"ECB": 2}, "CBC": {"CBC": 2}, "CTR": {"CTR": 3}, "CFB": {"CFB": 1}, "GCM": {"GCM": 19}, "CCM": {"CCM": 2}}, "ecc_curve": {"NIST": {"P-256": 18, "P-384": 24, "P-521": 20}}, "crypto_engine": {}, "tls_cipher_suite": {"TLS": {"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1, "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1}}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 13}, "IBM": {"SSC": 5}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 7, "FIPS186-4": 27, "FIPS 186-4": 9, "FIPS 198-1": 5, "FIPS 180-4": 5, "FIPS 186-2": 1, "FIPS 186-5": 1, "FIPS186": 4}, "NIST": {"SP 800-38A": 3, "SP 800-38D": 1, "SP 800-90A": 1, "SP 800-56A": 6, "SP 800-135": 3, "SP 800-90B": 1}, "PKCS": {"PKCS 1": 2}, "RFC": {"RFC7627": 1, "RFC 5288": 1, "RFC 5246": 1, "RFC762": 4}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "in Section 11 will result in the module operating in a non-compliant state, which is considered out of scope of this validation. 11.2 Administrator Guidance The Administrator Guidance can be obtained from": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 1391056, "pdf_is_encrypted": false, "pdf_number_of_pages": 80, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260624083911-04'00'", "/ModDate": "D:20260624083911-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://docs.paloaltonetworks.com/panorama/11-1/panorama-admin", "https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/advanced-url-filtering/advanced-url-filtering-administration.pdf"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["SHA-1A3453", "HMAC-SHA2-224A3453", "SHA2-256A3453", "AES-CFB128A3453", "ECDSA KeyVer (FIPS186-4)A3453", "RSA SigGen (FIPS186-4)A3453", "KDF SSHA3453", "RSA SigVer (FIPS186-4)A3453", "TLS v1.2 KDF RFC7627A3453", "SHA2-512A3453", "AES-CTRA3453", "Safe Primes Key GenerationA3453", "AES-CBCA3453", "Counter DRBGA3453", "HMAC-SHA2-256A3453", "AES-GCMA3453", "ECDSA SigVer (FIPS186-4)A3453", "KAS-ECC-SSC Sp800-56Ar3A3453", "SHA2-384A3453", "RSA KeyGen (FIPS186-4)A3453", "HMAC-SHA2-512A3453", "HMAC-SHA2-384A3453", "Safe Primes Key VerificationA3453", "ECDSA KeyGen (FIPS186-4)A3453", "SHA2-224A3453", "KDF SNMPA3453", "KAS-FFC-SSC Sp800-56Ar3A3453", "HMAC-SHA-1A3453", "ECDSA SigGen (FIPS186-4)A3453"]}, "extracted_versions": {"_type": "Set", "elements": ["11.2", "11.1"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "2927af5c0889c25aed0914bbf628d8c1d6413171f405bc8b9c1963c45f1f7c1a", "txt_hash": "9d2dd25b96ec2d654f801cf9aa0d50427ba1972a3c00cf76c2264376d1b737c0", "json_hash": null}}}