PAN-OS 11.1 and 11.2 VM-Series

Certificate details

Certificate ID #5351
Status active
Validation dates 25.06.2026
Sunset date 24-06-2031
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When installed, initialized and configured as specified in Section 11.1 of the Security Policy
Exceptions
  • Roles, services, and authentication: Level 3
  • Physical security: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A
Description Palo Alto Networks offers a full line of next-generation security appliances. The PAN-OS VM-Series is a software cryptographic module and requires an underlying general purpose computer (GPC) environment.
Vendor Palo Alto Networks, Inc. http://www.paloaltonetworks.com
Lab Leidos Accredited Testing & Evaluation (AT&E) Lab
Algorithms
  • AES-CBCA3454
  • AES-CFB128A3454
  • AES-CTRA3454
  • AES-GCMA3454
  • Counter DRBGA3454
  • ECDSA KeyGen (FIPS186-4)A3454
  • ECDSA KeyVer (FIPS186-4)A3454
  • ECDSA SigGen (FIPS186-4)A3454
  • ECDSA SigVer (FIPS186-4)A3454
  • HMAC-SHA-1A3454
  • HMAC-SHA2-224A3454
  • HMAC-SHA2-256A3454
  • HMAC-SHA2-384A3454
  • HMAC-SHA2-512A3454
  • KAS-ECC-SSC Sp800-56Ar3A3454
  • KAS-FFC-SSC Sp800-56Ar3A3454
  • KDF IKEv2A3454
  • KDF SNMPA3454
  • KDF SSHA3454
  • RSA KeyGen (FIPS186-4)A3454
  • RSA SigGen (FIPS186-4)A3454
  • RSA SigVer (FIPS186-4)A3454
  • Safe Primes Key GenerationA3454
  • Safe Primes Key VerificationA3454
  • SHA-1A3454
  • SHA2-224A3454
  • SHA2-256A3454
  • SHA2-384A3454
  • SHA2-512A3454
  • TLS v1.2 KDF RFC7627A3454
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-256, AES-128, AES-192, AES, AES-, CAST, HMAC, HMAC-SHA-256
Asymmetric Algorithms
RSA 2048, RSA 3072, RSA 4096, ECDHE, ECDH, ECDSA, ECC, Diffie-Hellman, DHE, DH
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Agreement
Protocols
SSH, SSHv2, TLS v1.2, TLSv1.2, TLS, TLS 1.2, TLSv1.3, IKEv2, IKE, IPsec, VPN
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
CBC, CTR, CFB, GCM
TLS cipher suites
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

Trusted Execution Environments
PSP, SSC
Vendor
Microsoft

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5351,
  "dgst": "121076a4131f0eb8",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA2-512A3454",
        "AES-CFB128A3454",
        "HMAC-SHA-1A3454",
        "RSA KeyGen (FIPS186-4)A3454",
        "HMAC-SHA2-384A3454",
        "SHA2-256A3454",
        "Safe Primes Key VerificationA3454",
        "SHA2-512A3454",
        "AES-CBCA3454",
        "RSA SigGen (FIPS186-4)A3454",
        "HMAC-SHA2-256A3454",
        "KDF SSHA3454",
        "ECDSA KeyVer (FIPS186-4)A3454",
        "SHA-1A3454",
        "SHA2-224A3454",
        "SHA2-384A3454",
        "AES-CTRA3454",
        "RSA SigVer (FIPS186-4)A3454",
        "Counter DRBGA3454",
        "KAS-ECC-SSC Sp800-56Ar3A3454",
        "HMAC-SHA2-224A3454",
        "KDF IKEv2A3454",
        "AES-GCMA3454",
        "ECDSA KeyGen (FIPS186-4)A3454",
        "KDF SNMPA3454",
        "Safe Primes Key GenerationA3454",
        "TLS v1.2 KDF RFC7627A3454",
        "#A3454",
        "KAS-FFC-SSC Sp800-56Ar3A3454",
        "ECDSA SigGen (FIPS186-4)A3454",
        "ECDSA SigVer (FIPS186-4)A3454"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "11.1",
        "11.2"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3454",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3454",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3454",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3454",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3454",
            "properties": "Prediction Resistance - No, Yes Mode - AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3454",
            "properties": "Key Length - Key Length: 256-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3454",
            "properties": "Key Length - Key Length: 256-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3454",
            "properties": "Key Length - Key Length: 256-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3454",
            "properties": "Key Length - Key Length: 256-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3454",
            "properties": "Key Length - Key Length: 256-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3454",
            "properties": "Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3454",
            "properties": "Domain Parameter Generation Methods - MODP-2048, MODP-3072, MODP-4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDF IKEv2 (CVL)",
            "cavpCertName": "A3454",
            "properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 256, 384,",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "2048 Derived Keying Material Length - Derived Keying Material Length: 800-3072 Increment 8 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": ""
          },
          {
            "algorithm": "KDF SNMP (CVL)",
            "cavpCertName": "A3454",
            "properties": "Password Length - Password Length: 64, 2048",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A3454",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2- 512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3454",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3454",
            "properties": "Safe Prime Groups - MODP-2048, MODP- 3072, MODP-4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A3454",
            "properties": "Safe Prime Groups - MODP-2048, MODP- 3072, MODP-4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3454",
            "properties": "Message Length - Message Length: 8-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3454",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3454",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3454",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3454",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A3454",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Networking parameter configurati on, logging configurati on, and other non- security relevant configurati on",
            "indicator": "Configuration/ System Logs",
            "inputs": "Input configura tions for other setup functions",
            "name": "Other Configur ation",
            "outputs": "Module uses configur ation",
            "rolesSspAccess": "Crypto Officer - CO, User, RA VPN Password: G,W,E - DHE/ECD HE Shared Secret Z: G,R,E - DRBG Key: G,E - DRBG Seed : G,E - DRBG V: G,E - ECDSA Private Keys : G,W,E - Entropy Input String: G,E - IKEv2 SKEYSEE D: G,R,E - RSA Private Keys: G,W,E - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Componen ts: G,E,Z - SSH DHE/ECD HE Public Componen ts: G,R,W,E,Z - SSH",
            "secFunImpl": "KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC (IPSec/IKE) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC (IPSec/IKE) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer TLS RSA KeyGen"
          },
          {
            "description": "Description",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Host Public Key: G,R,W,E - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - TLS Encryption Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z",
            "secFunImpl": "Functions TLS RSA SigGen TLS RSA SigVer TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer Session Encryption/De cryption (SSH) Session Encryption/De cryption (TLSv1.2) Session Encryption/De cryption (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Authentication (SMPv3) SSHv2 Keying Materials Development TLSv1.2 Keying Materials Development SNMPv3 Keying Materials Development"
          },
          {
            "description": "Configurin g and managing cryptograp hic parameters and setting/mo difying",
            "indicator": "Configuration/ System Logs",
            "inputs": "Input configura tion for various cryptogra phic functions",
            "name": "Security Configur ation Manage ment",
            "outputs": "Module uses the configur ation for cryptogr aphic purpose s",
            "rolesSspAccess": "Crypto Officer - CA Certificate s: G,R,W,E - CO, User, RA VPN",
            "secFunImpl": "KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen"
          },
          {
            "description": "security policy, including creating User accounts and additional CO accounts",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Password: G,W,E - DHE/ECD HE Shared Secret Z: G,R,E - DRBG Key: G,E - DRBG Seed : G,E - DRBG V: G,E - ECDSA Private Keys : G,W,E - ECDSA Public Keys: G,R,W,E - Entropy Input String: G,E - IKEv2 SKEYSEE D: G,R,E - Protocol Secrets: W,E - Public key for software content load test: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentica tion Key: G,E,Z - SNMPv3 Authentica",
            "secFunImpl": "(TLSv1.2) KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC (IPSec/IKE) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC (IPSec/IKE) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer Session"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "tion Secret: W,E - SNMPv3 Privacy Secret: W,E - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Componen ts: G,E,Z - SSH DHE/ECD HE Public Componen ts: G,R,W,E,Z - SSH Host Public Key: G,R,W,E - SSH Session Encryption Keys: G,E,Z - TLS DHE/ECD HE Private Componen ts: G,E,Z - TLS DHE/ECD HE Public Componen ts: G,R,W,E,Z - TLS Encryption Keys: G,E,Z",
            "secFunImpl": "Encryption/De cryption (SSH) Session Encryption/De cryption (TLSv1.2) Session Encryption/De cryption (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Authentication (SMPv3) SSHv2 Keying Materials Development TLSv1.2 Keying Materials Development SNMPv3 Keying Materials Development"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "Initiates self-tests and integrity test",
            "indicator": "System Logs",
            "inputs": "Self-test comman d or rebooting the module",
            "name": "Self- Tests",
            "outputs": "Status of the self- tests",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Provides status information of the module",
            "indicator": "Configuration/ System Logs",
            "inputs": "Initiate show status comman d",
            "name": "Show Status",
            "outputs": "Module provides status output of module",
            "rolesSspAccess": "Crypto Officer - CO, User, RA VPN Password: G,W,E - DRBG Key: G,E - DRBG Seed : G,E - DRBG V: G,E - ECDSA Private Keys : E - Entropy Input String: G,E - RSA Private Keys: E - SSH DHE/ECD HE Private Componen ts: G,E,Z - SSH DHE/ECD HE Public Componen ts:",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "G,R,W,E,Z - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - TLS DHE/ECD HE Private Componen ts: G,E,Z - TLS DHE/ECD HE Public Componen ts: G,R,W,E,Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Unauthenti cated User - CO, User, RA VPN Password: G,W,E - DRBG Key: G,E - DRBG Seed : G,E",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG V: G,E - ECDSA Private Keys : E - Entropy Input String: G,E - RSA Private Keys: E - SSH DHE/ECD HE Private Componen ts: G,E,Z - SSH DHE/ECD HE Public Componen ts: G,R,W,E,Z - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - TLS DHE/ECD HE Private Componen ts: G,E,Z - TLS DHE/ECD HE Public Componen ts: G,R,W,E,Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys:",
            "secFunImpl": ""
          },
          {
            "description": "Shows the version of the module",
            "indicator": "Version displayed via System Logs / CLI / UI",
            "inputs": "Input comman d for version",
            "name": "Show Version",
            "outputs": "Module displays version informati on",
            "rolesSspAccess": "Crypto Officer Unauthenti cated",
            "secFunImpl": "None"
          },
          {
            "description": "Provides a method to update the software of the module",
            "indicator": "Configuration/ System Logs",
            "inputs": "Uploadin g new software",
            "name": "Software Update",
            "outputs": "Status of the updated software installati on",
            "rolesSspAccess": "Crypto Officer - Public key for software content load test: E",
            "secFunImpl": "Software Load Test"
          },
          {
            "description": "Read-only of non- security relevant configurati on",
            "indicator": "Configuration/ System Logs",
            "inputs": "Initiate comman d to read configura tion",
            "name": "View Other Configur ation",
            "outputs": "Module provides configur ation details",
            "rolesSspAccess": "Crypto Officer - CO, User, RA VPN Password: W,E User - CO, User, RA VPN Password: W,E",
            "secFunImpl": "None"
          },
          {
            "description": "Provide network access for remote users or site-to-site connection",
            "indicator": "Configuration/ System Logs",
            "inputs": "Initiating VPN connecti ons",
            "name": "VPN",
            "outputs": "Module provides VPN connecti on",
            "rolesSspAccess": "Remote Access VPN (RA VPN) - CA Certificate s: W,E - DRBG Key: G,E - DRBG Seed : G,E - DRBG V: G,E - ECDSA Private",
            "secFunImpl": "KAS-ECC- KeyGen (IPSec/IKE) KAS-FFC- KeyGen (IPSec/IKE) KAS-ECC (IPSec/IKE) IPSec/IKE RSA KeyGen IPSec/IKE RSA SigGen IPSec/IKE RSA SigVer IPSec/IKE"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Keys : E - ECDSA Public Keys: W,E - Entropy Input String: G,E - RA VPN IPSec Authentica tion : G,E,Z - RA VPN IPSec Session Keys: G,E,Z - RSA Private Keys: E - RSA Public Keys: W,E - S-S VPN IPSec Pre- Shared Keys: W,E - S-S VPN IPSec/IKE DHE or ECDHE Private Componen ts: G,E,Z - S-S VPN IPSec/IKE DHE or ECDHE Public Componen ts: G,R,W,E,Z - S-S VPN IPSec/IKE Session Keys: G,E,Z - TLS DHE/ECD HE Private",
            "secFunImpl": "ECDSA KeyGen IPSec/IKE ECDSA SigGen IPSec/IKE ECDSA SigVer Session Encryption/De cryption (IPSec/IKE) Session Authentication (IPSec/IKE) IPSec/IKE Keying Materials Development CKG"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Componen ts: G,E,Z - TLS DHE/ECD HE Public Componen ts: G,R,W,E,Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Site-to-Site VPN (S-S VPN) - CA Certificate s: W,E - DRBG Key: G,E - DRBG Seed : G,E - DRBG V: G,E - ECDSA Private Keys : E - ECDSA Public Keys: W,E - Entropy Input String: G,E - RA VPN IPSec Authentica tion : G,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- RA VPN IPSec Session Keys: G,E,Z - RSA Private Keys: E - RSA Public Keys: W,E - S-S VPN IPSec Pre- Shared Keys: W,E - S-S VPN IPSec/IKE DHE or ECDHE Private Componen ts: G,E,Z - S-S VPN IPSec/IKE DHE or ECDHE Public Componen ts: G,R,W,E,Z - S-S VPN IPSec/IKE Session Keys: G,E,Z - TLS DHE/ECD HE Private Componen ts: G,E,Z - TLS DHE/ECD HE Public Componen ts: G,R,W,E,Z - TLS Encryption Keys: G,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "Destroys (Zeroizes) all keys in the module",
            "indicator": "Zeroization indicator",
            "inputs": "Initiating zeroizati on comman d",
            "name": "Zeroize",
            "outputs": "Status of the zeroizati on process",
            "rolesSspAccess": "Unauthenti cated - CA Certificate s: Z - CO, User, RA VPN Password: Z - DHE/ECD HE Shared Secret Z: Z - DRBG Key: Z - DRBG Seed : Z - DRBG V: Z - ECDSA Private Keys : Z - ECDSA Public Keys: Z - Entropy Input String: Z - IKEv2 SKEYSEE D: Z - Protocol Secrets: Z - Public key for software content",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "load test: Z - RA VPN IPSec Authentica tion : Z - RA VPN IPSec Session Keys: Z - RSA Private Keys: Z - RSA Public Keys: Z - S-S VPN IPSec Pre- Shared Keys: Z - S-S VPN IPSec/IKE Authentica tion Keys: Z - S-S VPN IPSec/IKE DHE or ECDHE Private Componen ts: Z - S-S VPN IPSec/IKE DHE or ECDHE Public Componen ts: Z - S-S VPN IPSec/IKE Session Keys: Z - SNMPv3 Authentica tion Key: Z - SNMPv3 Authentica tion Secret: Z - SNMPv3",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Privacy Secret: Z - SNMPv3 Session Key: Z - SSH Client Public Key: Z - SSH DHE/ECD HE Private Componen ts: Z - SSH DHE/ECD HE Public Componen ts: Z - SSH Host Public Key: Z - SSH Session Authentica tion Keys: Z - SSH Session Encryption Keys: Z - TLS DHE/ECD HE Private Componen ts: Z - TLS DHE/ECD HE Public Componen ts: Z - TLS Encryption Keys: Z - TLS HMAC Keys: Z - TLS Master",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Secret: Z - TLS Pre- Master Secret: Z",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [
          {
            "description": "The modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits",
            "mechanism": "RSA SigVer (FIPS186- 4) (A3454)",
            "name": "RSA- Based Certificate",
            "perMinute": "The probability of successfully authenticating to the module within a one minute period is 288,000,000/(2112). The module supports at most 4,800,000 new",
            "strength": "With a minimum modulus size of 2048, the probability that a random attempt will succeed is 1/(2^112)."
          },
          {
            "description": "The modules support ECDSA public-key based authentication mechanism using a minimum ECDSA curve of P-256",
            "mechanism": "ECDSA SigVer (FIPS186- 4) (A3454)",
            "name": "ECDSA- Based Certificate",
            "perMinute": "sessions per second. The probability of successfully authenticating to the module within a one minute period is 288,000,000/(2112). The module supports at most 4,800,000 new sessions per second.",
            "strength": "With a minimum curve of P-256, the probability that a random attempt will succeed is 1/(2^128)."
          },
          {
            "description": "Password based authentication",
            "mechanism": "Password Based",
            "name": "Password",
            "perMinute": "The probability of successfully authenticating to the module within one minute is 10/(958). The firewall\u0027s configuration supports at most ten failed attempts to",
            "strength": "The minimum length is eight (8) characters (95 possible characters). The probability that a random attempt will succeed or a false"
          },
          {
            "description": "",
            "mechanism": "",
            "name": "",
            "perMinute": "authenticate in a one- minute period.",
            "strength": "acceptance will occur is 1/(958)."
          },
          {
            "description": "PSK authentication",
            "mechanism": "Password Based",
            "name": "Pre- Shared Secret",
            "perMinute": "The probability of successfully authenticating to the module within a one minute period is 288,000,000/(956).",
            "strength": "The pre-shared key authentication method has a minimum security strength of 956. The probability of successfully authenticating to the module is 1/(956). The number of authentication attempts is limited by the number of new connections per second supported (4,800,000) on the fastest platform of the Palo Alto Networks firewalls."
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES GCM (A3454) Decrypt",
            "condition": "After each power- on or via self-test comman d",
            "details": "Decrypt",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES GCM (A3454) Encrypt",
            "condition": "After each power- on or via self-test comman d",
            "details": "Encrypt",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB Decrypt (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Decrypt",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "128 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "SP 800-90Arev1 Instantiate/Generate/Rese ed Known Answer Tests",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA / KAS-ECC",
            "condition": "On session",
            "details": "ECDSA / KAS-ECC pairwise consistency test",
            "indicator": "System log message s",
            "testMethod": "PCT",
            "testProps": "256 Bit Minimu m",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186 -4) (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Sign",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186 -4) (A3454)",
            "condition": "After each power- on or via self-test comman",
            "details": "Verify",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA-1 (A3454)",
            "condition": "d After each power- on or via self-test comman d",
            "details": "Keyed Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "160 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 224 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Keyed Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "224 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 256 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Keyed Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-",
            "condition": "After each power-",
            "details": "Keyed Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "384 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "384 (A3454)",
            "condition": "on or via self-test comman d",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 512 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Keyed Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "512 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS- ECC-SSC Sp800- 56Ar3 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "KAS Computation",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC",
            "condition": "On session",
            "details": "KAS-FCC pairwise consistency test",
            "indicator": "System log message s",
            "testMethod": "PCT",
            "testProps": "2048 Bit Minimu m",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS- FFC-SSC Sp800- 56Ar3 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "KAS Computation",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "2048 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF IKEv2 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "IKEv2 with SHA-256",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "SSHv2 with SHA-256",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF TLS (A3454)",
            "condition": "After each power- on or via self-test",
            "details": "TLSv1.2 with SHA-256",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA",
            "condition": "d On session",
            "details": "RSA pairwise consistency test",
            "indicator": "System log message s",
            "testMethod": "PCT",
            "testProps": "2048 Bit Minimu m",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186 -4) (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Sign",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186 -4) (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Verify",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generatio n (A3454)",
            "condition": "On session",
            "details": "KAS-FCC pairwise consistency test",
            "indicator": "System log message s",
            "testMethod": "PCT",
            "testProps": "2048 Bit Minimu m",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "SHA-1 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "160 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2- 256 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "256 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2- 384 (A3454)",
            "condition": "After each power- on or via self-test comman d",
            "details": "Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "384 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2- 512 (A3454)",
            "condition": "After each power-",
            "details": "Hash",
            "indicator": "Self-test output message",
            "testMethod": "KAT",
            "testProps": "512 Bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "on or via self-test comman d",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "Software Load Test",
            "condition": "On session",
            "details": "Software load test on content load",
            "indicator": "System log message s",
            "testMethod": "SW Load Test",
            "testProps": "2048 Bits",
            "type": "SW/FW Load"
          },
          {
            "algorithmOrTest": "SP 800- 90B RCT/APT Health Tests on Entropy Source",
            "condition": "After each power- on or via self-test comman d",
            "details": "Health tests done on entropy source",
            "indicator": "Self-test output message",
            "testMethod": "Fault- Detectio n Test",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SP 800- 56A Rev 3 Assuranc e Tests",
            "condition": "On session",
            "details": "Assurance tests for SP 800-56A Rev3",
            "indicator": "System log message s",
            "testMethod": "Critical Function s",
            "testProps": "N/A",
            "type": "Critical Functio n"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "PCT / Critical functions test",
            "description": "Module fails a PCT or critical functions test",
            "indicator": "System log prints an error message.",
            "name": "Conditional Pairwise Consistency or Critical Functions Test Failure",
            "recoveryMethod": "Reset session"
          },
          {
            "conditions": "Signature verification failure",
            "description": "Signature verification fails on software load",
            "indicator": "System prints Invalid image message.",
            "name": "Conditional Software Load Test Failure",
            "recoveryMethod": "N/A"
          },
          {
            "conditions": "Self-test or Integrity Test failure",
            "description": "Module fails a self-test or integrity test",
            "indicator": "FIPS-CC mode failure. \u003cAlgorithm test\u003e failed.",
            "name": "Self-Test / Integrity Test Failure",
            "recoveryMethod": "Reboot Module or Factory Reset"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "The module has one approved mode of operation and is always in approved mode after initialization",
            "name": "Approved Mode",
            "statusIndicator": "Global indicator (\"FIPS-CC\")",
            "type": "Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Power supplies",
            "logicalInterface": "Power",
            "physicalPort": "N/A"
          },
          {
            "data": "Self-test status output",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          },
          {
            "data": "HTTPS, TLS, SNMP, IPsec, and SSH traffic data.",
            "logicalInterface": "Data Input Data Output Control Input Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "RSA-Based Certificate ECDSA-Based Certificate Password Pre-Shared Secret",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Identity"
          },
          {
            "authMethodList": "RSA-Based Certificate ECDSA-Based Certificate Password Pre-Shared Secret",
            "name": "User",
            "operatorType": "User",
            "type": "Identity"
          },
          {
            "authMethodList": "RSA-Based Certificate ECDSA-Based Certificate Password Pre-Shared Secret",
            "name": "Remote Access VPN (RA VPN)",
            "operatorType": "CO",
            "type": "Identity"
          },
          {
            "authMethodList": "Password Pre-Shared Secret",
            "name": "Site-to-Site VPN (S-S VPN)",
            "operatorType": "CO",
            "type": "Identity"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "3",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "3",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A3454)",
            "details": "Signature Verification",
            "indicator": "Self-Test successful",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A3454)",
            "details": "Keyed Checksum",
            "indicator": "Self-Test successful",
            "testMethod": "KAT",
            "testProps": "SHA2- 256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "External (Outside of Module\u0027s Boundary)",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Module Public Key Output",
            "sfiAlgo": "",
            "source": "HDD"
          },
          {
            "dest": "HDD",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Password/Secret Input via SSHv2 encrypted by AES and HMAC",
            "sfiAlgo": "KTS (SSHv2 with AES and HMAC)",
            "source": "External (Outside of Module\u0027s Boundary)"
          },
          {
            "dest": "HDD",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Password/Secret Input via SSHv2 encrypted by AES-GCM",
            "sfiAlgo": "KTS (SSHv2 with AES- GCM)",
            "source": "External (Outside of Module\u0027s Boundary)"
          },
          {
            "dest": "HDD",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Password/Secret Input via TLSv1.2 encrypted by AES and HMAC",
            "sfiAlgo": "KTS (TLSv1.2 with AES and HMAC)",
            "source": "External (Outside of Module\u0027s Boundary)"
          },
          {
            "dest": "HDD",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Password/Secret Input via TLSv1.2 encrypted by AES-GCM",
            "sfiAlgo": "KTS (TLSv1.2 with AES- GCM)",
            "source": "External (Outside of Module\u0027s Boundary)"
          },
          {
            "dest": "HDD",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Peer Public Key Input",
            "sfiAlgo": "",
            "source": "External (Outside of Module\u0027s Boundary)"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Operator powers the module off or session terminates",
            "method": "Power Cycle / Session Termination",
            "operatorId": "Command via CLI or WebUI or by unplugging module",
            "rationale": "Powering off the module or terminating the session will erase all SSPs stored in the RAM of the module."
          },
          {
            "description": "CO issues zeroization service",
            "method": "Zeroization Command",
            "operatorId": "Entering into maintenance mode and selecting Factory Reset",
            "rationale": "The zeroization command will erase all SSPs stored in the RAM or in the Flash of the module."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Non-Volatile Memory",
            "name": "HDD",
            "persistance": "Static"
          },
          {
            "description": "Volatile Memory",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Dell PowerEdge R740",
            "hypervisorHostOs": "Hyper-V 2019 on Microsoft Hyper-V Server 2019",
            "operatingSystem": "N/A",
            "paa_pai": "No",
            "processors": "Intel Xeon Gold 6248",
            "version": "11.1.8 11.2.5"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R740",
            "hypervisorHostOs": "KVM 4 on Ubuntu 20.04",
            "operatingSystem": "N/A",
            "paa_pai": "No",
            "processors": "Intel Xeon Gold 6248",
            "version": "11.1.8 11.2.5"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R740",
            "hypervisorHostOs": "VMware ESXi v7.0",
            "operatingSystem": "N/A",
            "paa_pai": "No",
            "processors": "Intel Xeon Gold 6248",
            "version": "11.1.8 11.2.5"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Symmetric and Asymmetric",
            "implName": "N/A",
            "name": "CKG",
            "reference": "Cryptographic Key Generation; SP 800- 133rev2 and IG D.H (symmetric keys and asymmetric seeds) from Section 4 Example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system)",
            "operatingSystem": "Amazon Web Services (AWS)"
          },
          {
            "hardwarePlatform": "x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system)",
            "operatingSystem": "Google Cloud Platform (GCP)"
          },
          {
            "hardwarePlatform": "x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system)",
            "operatingSystem": "Microsoft Azure"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 17
          },
          "ECDH": {
            "ECDH": 6,
            "ECDHE": 26
          },
          "ECDSA": {
            "ECDSA": 91
          }
        },
        "FF": {
          "DH": {
            "DH": 2,
            "DHE": 30,
            "Diffie-Hellman": 4
          }
        },
        "RSA": {
          "RSA 2048": 9,
          "RSA 3072": 1,
          "RSA 4096": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 3
        },
        "GCM": {
          "GCM": 24
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1,
          "IKEv2": 16
        },
        "IPsec": {
          "IPsec": 2
        },
        "SSH": {
          "SSH": 106,
          "SSHv2": 58
        },
        "TLS": {
          "TLS": {
            "TLS": 98,
            "TLS 1.2": 1,
            "TLS v1.2": 8,
            "TLSv1.2": 88,
            "TLSv1.3": 1
          }
        },
        "VPN": {
          "VPN": 65
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 8
        },
        "MAC": {
          "MAC": 5
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 20,
          "P-384": 36,
          "P-521": 22
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 1,
          "AES (128": 2,
          "AES 128/192/256": 1,
          "AES 256": 2,
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 3,
          "DRBG 2": 1,
          "HMAC- SHA-1": 1,
          "HMAC-SHA- 1": 5,
          "HMAC-SHA- 1, 160": 1,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-256": 2,
          "PKCS 1": 3,
          "RSA 2048": 9,
          "RSA 3072": 1,
          "RSA 4096": 1,
          "SHA-1": 8,
          "SHA-256": 5,
          "SHA-384": 1,
          "SHA-512": 1,
          "SHA2- 224": 1,
          "SHA2- 256": 4,
          "SHA2- 384": 2,
          "SHA2- 512": 3,
          "SHA2-224": 3,
          "SHA2-256": 8,
          "SHA2-384": 6,
          "SHA2-512": 5
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          },
          "SHA2": {
            "SHA-256": 5,
            "SHA-384": 1,
            "SHA-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 64
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 4,
          "FIPS 180-4": 5,
          "FIPS 186-2": 1,
          "FIPS 186-4": 9,
          "FIPS 186-5": 1,
          "FIPS 198-1": 5,
          "FIPS186": 4,
          "FIPS186-4": 33
        },
        "NIST": {
          "SP 800-135": 4,
          "SP 800-38A": 3,
          "SP 800-38D": 1,
          "SP 800-56A": 6,
          "SP 800-90A": 1,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5282": 1,
          "RFC 5288": 1,
          "RFC76": 3,
          "RFC7627": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 49,
            "AES-": 7,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 3
          },
          "CAST": {
            "CAST": 46
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 45,
            "HMAC-SHA-256": 1
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 14
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {
        "TLS": {
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1
        }
      },
      "vendor": {
        "Microsoft": {
          "Microsoft": 2
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA2-512A3454",
        "AES-CFB128A3454",
        "HMAC-SHA-1A3454",
        "RSA KeyGen (FIPS186-4)A3454",
        "HMAC-SHA2-384A3454",
        "SHA2-256A3454",
        "SHA2-512A3454",
        "AES-CBCA3454",
        "RSA SigGen (FIPS186-4)A3454",
        "HMAC-SHA2-256A3454",
        "KDF SSHA3454",
        "ECDSA KeyVer (FIPS186-4)A3454",
        "ECDSA SigGen (FIPS186-4)A3454",
        "SHA-1A3454",
        "SHA2-224A3454",
        "SHA2-384A3454",
        "AES-CTRA3454",
        "RSA SigVer (FIPS186-4)A3454",
        "Counter DRBGA3454",
        "HMAC-SHA2-224A3454",
        "KAS-ECC-SSC Sp800-56Ar3A3454",
        "KDF IKEv2A3454",
        "AES-GCMA3454",
        "ECDSA KeyGen (FIPS186-4)A3454",
        "KDF SNMPA3454",
        "Safe Primes Key GenerationA3454",
        "TLS v1.2 KDF RFC7627A3454",
        "KAS-FFC-SSC Sp800-56Ar3A3454",
        "Safe Primes Key VerificationA3454",
        "ECDSA SigVer (FIPS186-4)A3454"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A3454"
      ]
    },
    "policy_metadata": {
      "/CreationDate": "D:20260624083154-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260624083154-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 734365,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/pan-os/11-1/pan-os-admin/pan-os-admin.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 64
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "ad83a47d0a50ae4cbc7af8485fdfa4f5b3cf9b8dc069e64b9dcaec6a852c4fc5",
      "source_hash": "48375a99a655792f165f058ce66a9bb1759be6927672e95fda47f20e1bb50963",
      "txt_hash": "637114284309b79aba75ce7f8a4dc65cec84e22e58faad94cf3634fa049597c7"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2026_080726_0648.pdf",
    "date_sunset": "2031-06-24",
    "description": "Palo Alto Networks offers a full line of next-generation security appliances. The PAN-OS VM-Series is a software cryptographic module and requires an underlying general purpose computer (GPC) environment.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Roles, services, and authentication: Level 3",
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Life-cycle assurance: Level 3",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "PAN-OS 11.1 and 11.2 VM-Series",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-25",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Palo Alto Networks, Inc.",
    "vendor_url": "http://www.paloaltonetworks.com"
  }
}