Palo Alto Networks VM-Series

Certificate #2800

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 30.11.2016 , 11.01.2018 , 13.02.2018 , 21.02.2020
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The VM-Series allows you to protect your applications and data from cyber threats with our next-generation firewall security and advanced threat prevention features.
Tested configurations
  • CentOS 6.5 - KVM running on a Dell Power Edge R620
  • Citrix XenServer 6.1.0 running on a Citrix NetScaler SDX 11500 (single-user mode)
  • VMware ESXi 5.5 running on a Dell PowerEdge R730
Vendor Palo Alto Networks
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, CAST, RC4, DES, Triple-DES, Blowfish, Camellia, SEED, HMAC, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512
Asymmetric Algorithms
RSA 2048, RSA 3072, RSA 1024, ECDH, ECDHE, ECDSA, Diffie-Hellman, DHE, DH
Hash functions
SHA-1, SHA1, SHA-256, SHA-384, SHA-512, SHA-224, SHA256, SHA384, MD5, RIPEMD
Schemes
MAC, Key Exchange
Protocols
SSHv2, SSH, SSL, TLS, TLSv1.0, IKEv1, IKE, VPN
Randomness
DRBG, RNG
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM

Security level
Level 1

Standards
FIPS 140-2, FIPS 186-4, SP 800-52, SP 800-56A, SP 800-135, SP 800-90A, RFC 5288, RFC 6071

File metadata

Title PA-200, PA-500, PA-2000 Series, PA-3000 Series, PA-4000 Series, and PA-5000 Series Firewalls Security Policy
Author InfoGard
Creation date D:20180104123641-08'00'
Modification date D:20180104123646-08'00'
Pages 22
Creator Acrobat PDFMaker 11 for Word
Producer Adobe PDF Library 11.0

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2800,
  "dgst": "19d62f0f54e0697f",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "CVL#843",
        "CVL#844",
        "AES#4019",
        "KAS#844",
        "HMAC#2621",
        "KTS#4019",
        "KTS#2621",
        "SHS#3315",
        "DRBG#1197",
        "ECDSA#895",
        "CVL#846",
        "KAS#843",
        "CVL#845",
        "RSA#2062"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 3,
            "ECDHE": 5
          },
          "ECDSA": {
            "ECDSA": 16
          }
        },
        "FF": {
          "DH": {
            "DH": 7,
            "DHE": 8,
            "Diffie-Hellman": 7
          }
        },
        "RSA": {
          "RSA 1024": 1,
          "RSA 2048": 6,
          "RSA 3072": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 8
        },
        "CCM": {
          "CCM": 4
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 3
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 8
        },
        "OFB": {
          "OFB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 2,
          "IKEv1": 1
        },
        "SSH": {
          "SSH": 11,
          "SSHv2": 2
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 17,
            "TLSv1.0": 1
          }
        },
        "VPN": {
          "VPN": 30
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 28,
          "P-384": 24,
          "P-521": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "# 844": 1,
          "#843": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (128": 1,
          "AES 256 1197": 1,
          "AES 4019": 2,
          "AES-CBC 256": 1,
          "CVL 843": 1,
          "CVL 844": 1,
          "CVL 845": 1,
          "CVL 846": 1,
          "DRBG 2": 1,
          "HMAC 2621": 2,
          "HMAC-SHA- 512 2621": 2,
          "HMAC-SHA-1": 6,
          "HMAC-SHA-256": 6,
          "HMAC-SHA-384": 4,
          "HMAC-SHA-512": 2,
          "RSA 1024": 1,
          "RSA 2048": 6,
          "RSA 3072": 1,
          "SHA 512": 1,
          "SHA-1": 3,
          "SHA-224": 1,
          "SHA-256": 6,
          "SHA-384": 2,
          "SHA-512": 2,
          "SHA1": 3,
          "SHA256": 2,
          "SHA384": 2
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "RIPEMD": {
          "RIPEMD": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 3,
            "SHA1": 3
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 6,
            "SHA-384": 2,
            "SHA-512": 2,
            "SHA256": 2,
            "SHA384": 2
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 10
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 10,
          "FIPS 186-4": 1
        },
        "NIST": {
          "SP 800-135": 1,
          "SP 800-52": 1,
          "SP 800-56A": 3,
          "SP 800-90A": 1
        },
        "RFC": {
          "RFC 5288": 1,
          "RFC 6071": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 18
          },
          "CAST": {
            "CAST": 1
          },
          "RC": {
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 1
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 11,
            "HMAC-SHA-256": 3,
            "HMAC-SHA-384": 2,
            "HMAC-SHA-512": 1
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 1
          },
          "Camellia": {
            "Camellia": 1
          },
          "SEED": {
            "SEED": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "InfoGard",
      "/Company": "InfoGard Labaorties, Inc.",
      "/CreationDate": "D:20180104123641-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 11 for Word",
      "/Jive_LatestUserAccountName": "ashahhosse",
      "/Jive_VersionGuid": "32b21f59-4942-4f06-9afc-8be243c6e82d",
      "/ModDate": "D:20180104123646-08\u002700\u0027",
      "/Offisync_ProviderInitializationData": "https://loop.paloaltonetworks.com",
      "/Offisync_ServerID": "a14a2c2f-da46-4240-9725-91cb14d4c581",
      "/Offisync_UniqueId": "25202",
      "/Offisync_UpdateToken": "4",
      "/Producer": "Adobe PDF Library 11.0",
      "/SourceModified": "D:20180104203636",
      "/Title": "PA-200, PA-500, PA-2000 Series, PA-3000 Series, PA-4000 Series, and PA-5000 Series  Firewalls Security Policy",
      "pdf_file_size_bytes": 328344,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.paloaltonetworks.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 22
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "4b41506d63b76c3eee8673ecc523bfb84bb2496ab9a4959b3d7d47f9c0cba12d",
    "policy_txt_hash": "d474e60f4a867d26729d39e842f16d41de5181c36fb4f18ae1fae7b95f113f4f"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertNov2016.pdf",
    "date_sunset": null,
    "description": "The VM-Series allows you to protect your applications and data from cyber threats with our next-generation firewall security and advanced threat prevention features.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Physical Security: N/A",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Palo Alto Networks VM-Series",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "7.1.3",
    "tested_conf": [
      "CentOS 6.5 - KVM running on a Dell Power Edge R620",
      "Citrix XenServer 6.1.0 running on a Citrix NetScaler SDX 11500 (single-user mode)",
      "VMware ESXi 5.5 running on a Dell PowerEdge R730"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2016-11-30",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2018-01-11",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2018-02-13",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-02-21",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      }
    ],
    "vendor": "Palo Alto Networks",
    "vendor_url": "http://www.paloaltonetworks.com"
  }
}