Palo Alto Networks SD-WAN ION Core Crypto Module

Certificate #5392

Webpage information

Status active
Validation dates 10.07.2026
Sunset date 07-07-2029
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When installed, initialized and configured as specified in section 11.1 of the Security Policy and operated in approved mode
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Palo Alto Networks SD-WAN ION Core Crypto Module is utilized in hardware and software ION form factors. These enable the integration of a diverse set of wide area network (WAN) connection types, improve application performance and visibility, enhance security and compliance, and reduce the overall cost and complexity of your WAN.
Vendor Palo Alto Networks, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC, CBC-MAC
Asymmetric Algorithms
ECDH, ECDHE, ECDSA, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA1
Schemes
MAC
Protocols
SSH, SSHv2, TLS, TLSv1.2, TLS v1.2, IKEv2
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, P-521, P-224, Curve P-256
Block cipher modes
CTR, GCM

Trusted Execution Environments
PSP, SSC

Security level
Level 1

File metadata

Creation date D:20260710120708-04'00'
Modification date D:20260710120708-04'00'
Pages 42
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5392,
  "dgst": "6da233543753c62b",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": []
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 1,
            "ECDHE": 57
          },
          "ECDSA": {
            "ECDSA": 35
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 2
          },
          "DSA": {
            "DSA": 3
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CTR": {
          "CTR": 37
        },
        "GCM": {
          "GCM": 9
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv2": 3
        },
        "SSH": {
          "SSH": 51,
          "SSHv2": 43
        },
        "TLS": {
          "TLS": {
            "TLS": 69,
            "TLS v1.2": 1,
            "TLSv1.2": 60
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 25
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "Curve P-256": 5,
          "P-224": 8,
          "P-256": 43,
          "P-384": 12,
          "P-521": 8
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 3,
          "AES-128": 2,
          "AES-128/192/256": 1,
          "AES-192": 2,
          "AES-256": 5,
          "DRBG 256": 2,
          "HMAC- SHA1": 1,
          "HMAC-SHA-1": 6,
          "PKCS 1": 3,
          "SHA-1": 7,
          "SHA1": 1,
          "SHA2- 256": 7,
          "SHA2- 512": 1,
          "SHA2-256": 13,
          "SHA2-384": 9,
          "SHA2-512": 12
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 7,
            "SHA1": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 85
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 8,
          "FIPS 180-4": 7,
          "FIPS 186-4": 9,
          "FIPS 198-1": 7,
          "FIPS186-4": 14
        },
        "NIST": {
          "SP 800-135": 5,
          "SP 800-38A": 5,
          "SP 800-38D": 2,
          "SP 800-56A": 2,
          "SP 800-90A": 2,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 3
        },
        "RFC": {
          "RFC 5288": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10,
            "AES-": 9,
            "AES-128": 2,
            "AES-192": 2,
            "AES-256": 5
          },
          "CAST": {
            "CAST": 75
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 2,
            "HMAC": 37
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 9
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/CreationDate": "D:20260710120708-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260710120708-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 845215,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.paloaltonetworks.com/",
          "https://docs.paloaltonetworks.com/",
          "about:blank"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 42
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "44c7940f2b66977374b08e877cbcddcc831e825e4e7db93123f9ea7fe9ca7e98",
      "txt_hash": "b83b8a62f6b0565a68feef21ad5c036ea5ea61a66d86e92e5698d13cfb95e1e1"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in section 11.1 of the Security Policy and operated in approved mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf",
    "date_sunset": "2029-07-07",
    "description": "The Palo Alto Networks SD-WAN ION Core Crypto Module is utilized in hardware and software ION form factors. These enable the integration of a diverse set of wide area network (WAN) connection types, improve application performance and visibility, enhance security and compliance, and reduce the overall cost and complexity of your WAN.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Palo Alto Networks SD-WAN ION Core Crypto Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-07-10",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Palo Alto Networks, Inc.",
    "vendor_url": "http://www.paloaltonetworks.com"
  }
}