Page 1 of 80 Palo Alto Networks Inc. WildFire 10.2 WF-500 and WF-500-B FIPS 140-3 Non-Proprietary Security Policy Page 2 of 80 Table of Contents 1 General................................................................................................................................... 5 1.1 Overview .......................................................................................................................... 5 1.2 Security Levels ................................................................................................................. 5 2 Cryptographic Module Specification........................................................................................ 5 2.1 Description ....................................................................................................................... 5 2.2 Tested and Vendor Affirmed Module Version and Identification........................................ 7 2.3 Excluded Components...................................................................................................... 8 2.4 Modes of Operation.......................................................................................................... 8 2.5 Algorithms .......................................................................................................................10 2.6 Security Function Implementations..................................................................................12 2.7 Algorithm Specific Information .........................................................................................22 2.7.1 IG C.H Conformance.................................................................................................22 2.7.2 IG C.F Conformance .................................................................................................23 2.8 RBG and Entropy ............................................................................................................23 2.9 Key Generation................................................................................................................24 2.10 Key Establishment.........................................................................................................24 2.11 Industry Protocols..........................................................................................................24 3 Cryptographic Module Interfaces............................................................................................24 3.1 Ports and Interfaces ........................................................................................................24 4 Roles, Services, and Authentication.......................................................................................25 4.1 Authentication Methods ...................................................................................................25 4.2 Roles...............................................................................................................................26 4.3 Approved Services ..........................................................................................................26 4.4 Non-Approved Services...................................................................................................41 4.5 External Software/Firmware Loaded................................................................................42 5 Software/Firmware Security ...................................................................................................42 5.1 Integrity Techniques ........................................................................................................42 5.2 Initiate on Demand ..........................................................................................................42 6 Operational Environment........................................................................................................42 6.1 Operational Environment Type and Requirements ..........................................................42 7 Physical Security....................................................................................................................43 7.1 Mechanisms and Actions Required..................................................................................43 7.2 User Placed Tamper Seals..............................................................................................43 8 Non-Invasive Security ............................................................................................................55 9 Sensitive Security Parameters Management..........................................................................56 Page 3 of 80 9.1 Storage Areas .................................................................................................................56 9.2 SSP Input-Output Methods..............................................................................................56 9.3 SSP Zeroization Methods................................................................................................57 9.4 SSPs ...............................................................................................................................57 10 Self-Tests.............................................................................................................................72 10.1 Pre-Operational Self-Tests ............................................................................................72 10.2 Conditional Self-Tests....................................................................................................72 10.3 Periodic Self-Test Information........................................................................................75 10.4 Error States ...................................................................................................................77 10.5 Operator Initiation of Self-Tests .....................................................................................78 11 Life-Cycle Assurance ...........................................................................................................78 11.1 Installation, Initialization, and Startup Procedures..........................................................78 11.2 Administrator Guidance .................................................................................................79 11.3 Non-Administrator Guidance..........................................................................................79 11.4 Design and Rules ..........................................................................................................79 11.5 End of Life .....................................................................................................................79 12 Mitigation of Other Attacks ...................................................................................................80 Page 4 of 80 List of Tables Table 1: Security Levels............................................................................................................. 5 Table 2: Tested Module Identification – Hardware ..................................................................... 8 Table 3: Modes List and Description .......................................................................................... 8 Table 4: Approved Algorithms...................................................................................................12 Table 5: Vendor-Affirmed Algorithms ........................................................................................12 Table 6: Security Function Implementations..............................................................................22 Table 7: Entropy Certificates.....................................................................................................23 Table 8: Entropy Sources..........................................................................................................23 Table 9: Ports and Interfaces ....................................................................................................25 Table 10: Authentication Methods.............................................................................................26 Table 11: Roles.........................................................................................................................26 Table 12: Approved Services ....................................................................................................41 Table 13: Mechanisms and Actions Required ...........................................................................43 Table 14: Storage Areas ...........................................................................................................56 Table 15: SSP Input-Output Methods........................................................................................57 Table 16: SSP Zeroization Methods..........................................................................................57 Table 17: SSP Table 1..............................................................................................................64 Table 18: SSP Table 2..............................................................................................................72 Table 19: Pre-Operational Self-Tests........................................................................................72 Table 20: Conditional Self-Tests ...............................................................................................75 Table 21: Pre-Operational Periodic Information.........................................................................76 Table 22: Conditional Periodic Information................................................................................77 Table 23: Error States...............................................................................................................78 List of Figures Figure 1 - Block diagram............................................................................................................ 7 Page 5 of 80 1 General 1.1 Overview The WildFire 10.2 WF-500 and WF-500-B from Palo Alto Networks Inc., hereafter referred to as “Wildfire” or the “cryptographic module” is a multi-chip standalone hardware cryptographic module designed to fulfill FIPS 140-3 level 2 requirements. The WildFire 10.2 WF-500 and WF- 500-B module identifies unknown malware, zero-day exploits, and Advanced Persistent Threats (APTs) through dynamic analysis, and automatically disseminates protection in near real-time to help security teams meet the challenge of advanced cyber-attacks. Unknown files are analyzed by WildFire (WF) in a scalable sandbox environment where new threats are identified, and protections are automatically developed and delivered in the form of an update. The result is a unique, closed loop approach to controlling cyber threats that begins with positive security controls to reduce the attack surface, inspection of all traffic, ports, and protocols to block all known threats, and rapid detection of unknown threats by observing their actual behavior. The cryptographic module meets the overall requirements applicable to Level 2 security of FIPS 140-3. This document may freely be reproduced and distributed in its entirety. 1.2 Security Levels Section Title Security Level 1 General 2 2 Cryptographic module specification 2 3 Cryptographic module interfaces 2 4 Roles, services, and authentication 3 5 Software/Firmware security 2 6 Operational environment N/A 7 Physical security 2 8 Non-invasive security N/A 9 Sensitive security parameter management 2 10 Self-tests 2 11 Life-cycle assurance 3 12 Mitigation of other attacks N/A Overall Level 2 Table 1: Security Levels 2 Cryptographic Module Specification 2.1 Description Purpose and Use: The Palo Alto Networks, Inc. WildFire 10.2 WF-500 and WF-500-B is a multi-chip standalone hardware module. The cryptographic boundary includes all firmware components contained within the physical enclosure of the module. Figures below provide images of the module with Page 6 of 80 the physical kit’s opacity shields in place. See the Physical Security section for details regarding the module’s physical security mechanisms. Module Type: Hardware Module Embodiment: Multi-Chip Standalone Module Characteristics : Cryptographic Boundary: The cryptographic boundary includes the physical perimeter of the enclosure of the appliance and all logical components within. Please refer to the ‘Physical Security’ section for depictions of the module with the physical kit installed. WF-500 Front WF-500 Rear WF-500-B Front Page 7 of 80 WF-500-B Rear Figure 1 - Block diagram Tested Operational Environment’s Physical Perimeter (TOEPP): See above. 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Hardware: Page 8 of 80 Model and/or Part Number Hardware Version Firmware Version Processors Features WF-500 910-000097 Physical Kit: 920-000145 10.2.3-h1 Intel Xeon E5-2620 (Sandy Bridge) RJ45 interfaces, USB ports, LEDs WF-500- B 910-000270 Physical Kit: 920-000318 10.2.3-h1 Intel Xeon Silver 4316 (Ice Lake) RJ45 interfaces, USB ports, LEDs, SFP+ ports Table 2: Tested Module Identification – Hardware Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): N/A for this module. Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. 2.3 Excluded Components N/A 2.4 Modes of Operation Modes List and Description: Mode Name Description Type Status Indicator Approved Mode The module has one approved mode of operation and is always in approved mode after initialization Approved Global indicator ("FIPS-CC") Table 3: Modes List and Description The following procedure will initialize the modules into the Approved mode of operation: • Install module and interface connections in addition to the physical kit. Page 9 of 80 • The tamper-evident seals and opacity shields must be installed as per the ‘Physical Security’ section for the • module to operate in the Approved mode of operation. • Apply power to the device. • Establish a serial connection to the console port and command the module to enter into maintenance mode. o During initial boot up, break the boot sequence via the console port connection (by pressing the main button when instructed to do so) to access the main menu. • Select “Continue.” • Select the “Set FIPS-CC Mode” option to enter the Approved mode. • Select “Enable FIPS-CC Mode,” and press enter. • When prompted, select “Reboot” and the module will re-initialize and continue into the Approved mode. • The module will reboot. • In the Approved mode, the console port is available only as a status output port. • Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module o Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten The module will automatically indicate the Approved mode of operation in the following manner: • Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session. • Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port. Should one or more power-up self-tests fail, the module will not enter the Approved mode of operation. Feedback will consist of: • The module will output “FIPS-CC failure. • The module will reboot and enter a state in which the reason for the reboot can be determined by following the on-screen instructions. Note: Disabling Approved mode causes a complete factory reset, which is described in the Zeroization section below. Failure to follow the directions in the Approved Mode of Operation above and Section 11 will result in the module operating in a non-compliant state. Zeroization: To initiate the zeroization service, perform the following steps: • Access the module’s CLI via SSH, and command the module to enter maintenance mode; the module will reboot o Note: Establish a serial connection to the console port • After reboot, select “Continue. • Select “Factory Reset. • The module will perform a zeroization, and provide the following message once complete: o “Factory Reset Status: Success” Page 10 of 80 If the module does not successfully transition into the Approved mode of operation, or zeroization is performed, the module will be in an uninitialized state. It is required to initialize the module in order to perform cryptographic functions. Mode Change Instructions and Status: See Life-Cycle Assurance section. 2.5 Algorithms Approved Algorithms: Algorithm CAVP Cert Properties Reference AES-CBC A2906 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CFB128 A2906 Direction - Decrypt, Encrypt Key Length - 128 SP 800-38A AES-CTR A2906 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - No Counter Tests Performed - No SP 800-38A AES-GCM A2906 Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256 SP 800-38D Counter DRBG A2906 Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - Yes SP 800-90A Rev. 1 ECDSA KeyGen (FIPS186-4) A2906 Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates FIPS 186-4 ECDSA KeyVer (FIPS186-4) A2906 Curve - P-256, P-384, P-521 FIPS 186-4 ECDSA SigGen (FIPS186-4) A2906 Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 FIPS 186-4 ECDSA SigVer (FIPS186-4) A2906 Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 HMAC-SHA-1 A2906 MAC - MAC: 160 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 224 A2906 MAC - MAC: 224 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 Page 11 of 80 Algorithm CAVP Cert Properties Reference HMAC-SHA2- 256 A2906 MAC - MAC: 256 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 384 A2906 MAC - MAC: 384 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 512 A2906 MAC - MAC: 512 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 KAS-ECC- SSC Sp800- 56Ar3 A2906 Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800-56A Rev. 3 KAS-FFC-SSC Sp800-56Ar3 A2906 Domain Parameter Generation Methods - MODP- 2048 Scheme - dhEphem - KAS Role - initiator, responder SP 800-56A Rev. 3 KDF IKEv2 (CVL) A2906 Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 256, 384, 2048 Derived Keying Material Length - Derived Keying Material Length: 800-3072 Increment 8 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 KDF SNMP (CVL) A2906 Password Length - Password Length: 64, 2048 Engine ID - 80001F88043030303030343935323630 SP 800-135 Rev. 1 KDF SSH (CVL) A2906 Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-512 SP 800-135 Rev. 1 KDF TLS (CVL) A2906 TLS Version - v1.2 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 RSA KeyGen (FIPS186-4) A2906 Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Private Key Format - Standard FIPS 186-4 RSA SigGen (FIPS186-4) A2906 Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 FIPS 186-4 RSA SigVer (FIPS186-4) A2906 Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 FIPS 186-4 Safe Primes Key Generation A2906 Safe Prime Groups - MODP-2048 SP 800-56A Rev. 3 Safe Primes Key Verification A2906 Safe Prime Groups - MODP-2048 SP 800-56A Rev. 3 SHA-1 A2906 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 Page 12 of 80 Algorithm CAVP Cert Properties Reference SHA2-224 A2906 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-256 A2906 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-384 A2906 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-512 A2906 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 Table 4: Approved Algorithms Note: Only the algorithms specified in the table above are supported by the module in approved mode of operation. Vendor-Affirmed Algorithms: Name Properties Implementation Reference CKG Key Type:Asymmetric N/A SP 800-133rev2 Section 4 example 1 Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module. 2.6 Security Function Implementations Name Type Description Properties Algorithms Firmware Load Test DigSig-SigVer Signature verification for firmware load test RSA SigVer (FIPS186-4): (A2906) SHA2-256: (A2906) IPSec/IKE ECDSA KeyGen AsymKeyPair- KeyGen CKG ECDSA KeyGen for IPSec/IKEv2 ECDSA KeyGen (FIPS186-4): Page 13 of 80 Name Type Description Properties Algorithms (A2906) CKG: () IPSec/IKE ECDSA SigGen DigSig-SigGen ECDSA SigGen for IPSec/IKEv2 ECDSA SigGen (FIPS186-4): (A2906) IPSec/IKE ECDSA SigVer DigSig-SigVer ECDSA SigVer for IPSec/IKEv2 ECDSA SigVer (FIPS186-4): (A2906) IPSec/IKE RSA KeyGen AsymKeyPair- KeyGen CKG RSA KeyGen for IPSec/IKEv2 RSA KeyGen (FIPS186-4): (A2906) CKG: () IPSec/IKE RSA SigGen DigSig-SigGen RSA SigGen for IPSec/IKEv2 RSA SigGen (FIPS186-4): (A2906) IPSec/IKE RSA SigVer DigSig-SigVer RSA SigVer for IPSec/IKEv2 RSA SigVer (FIPS186-4): (A2906) IPSec/IKEv2 Keying Materials Development KAS-135KDF IPSec/IKE session keying materials, used to derive IPSec/IKE session keys HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) HMAC-SHA2- 512: (A2906) KDF IKEv2: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) KAS-ECC (IPSec/IKE) KAS-Full Full KAS-ECC Key Agreement used for IPSec/IKEv2 service Caveat:P-256 or P-384 curves providing 128 or 192 bits of encryption strength IG: IG D.F Scenario 2 Path 2 split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL KAS-ECC- SSC Sp800- 56Ar3: (A2906) KDF IKEv2: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) HMAC-SHA2- 256: (A2906) HMAC-SHA2- Page 14 of 80 Name Type Description Properties Algorithms 384: (A2906) HMAC-SHA2- 512: (A2906) KAS-ECC (SSH) KAS-Full Full KAS-ECC Key Agreement used for SSHv2 service Caveat:P-256, P-384, and P- 521 curves providing 128, 192, or 256 bits of encryption strength IG:IG D.F Scenario 2 Path 2 split Key Confirmation:No Key Derivation:No SHA-1: (A2906) SHA2-256: (A2906) SHA2-512: (A2906) KDF SSH: (A2906) KAS-ECC- SSC Sp800- 56Ar3: (A2906) KAS-ECC (TLSv1.2) KAS-Full Full KAS-ECC Key Agreement used for TLSv1.2 service Caveat:P-256, P-384, and P- 521 curves providing 128, 192, or 256 bits of encryption strength IG:D.F Scenario 2 Path 2 Key Confirmation:No Key Derivation:No HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) KDF TLS: (A2906) KAS-ECC- SSC Sp800- 56Ar3: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) KAS-ECC-KeyGen (IPSec/IKE) CKG KAS-KeyGen KAS ECC keygen used in IPSec/IKEv2 service Strength:P-256, P-384, and P- 521 curves providing 128, 192, or 256 bits of encryption strength Counter DRBG: (A2906) CKG: () KAS-ECC-KeyGen (SSH) CKG KAS-KeyGen KAS ECC keygen used in SSHv2 service Strength:P-256, P-384, and P- 521 curves providing 128, 192, or 256 bits of encryption strength Counter DRBG: (A2906) CKG: () KAS-ECC-KeyGen (TLSv1.2) CKG KAS-KeyGen KAS ECC keygen used in TLSv1.2 service Strength:P-256, P-384, and P- 521 curves providing 128, Counter DRBG: (A2906) CKG: () Page 15 of 80 Name Type Description Properties Algorithms 192, or 256 bits of encryption strength KAS-FFC (IPSec/IKE) KAS-Full Full KAS-FFC Key Agreement used for IPSec/IKEv2 service Caveat:2048 bit keys providing 112 bits of encryption strength IG:IG D.F Scenario 2 Path 2 Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL KAS-FFC-SSC Sp800-56Ar3: (A2906) KDF IKEv2: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) Safe Primes Key Generation: (A2906) Safe Primes Key Verification: (A2906) KAS-FFC (SSH) KAS-Full Full KAS-FFC Key Agreement used for SSHv2 service Caveat:2048-bit key providing 112 bits of encryption strength IG:IG D.F Scenario 2 Path 2 split Key Confirmation:No Key Derivation :IG 2.4.B SP 800-135rev1 CVL HMAC-SHA-1: (A2906) HMAC-SHA2- 256: (A2906) HMAC-SHA2- 512: (A2906) KDF SSH: (A2906) KAS-FFC-SSC Sp800-56Ar3: (A2906) SHA-1: (A2906) SHA2-256: (A2906) SHA2-512: (A2906) Safe Primes Key Generation: (A2906) Safe Primes Key Verification: (A2906) KAS-FFC (TLSv1.2) KAS-Full Full KAS-FFC Key Agreement Caveat:2048-bit key providing HMAC-SHA2- 256: (A2906) Page 16 of 80 Name Type Description Properties Algorithms used for TLSv1.2 service 112 bits of encryption strength IG:IG D.F Scenario 2 Path 2 split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL HMAC-SHA2- 384: (A2906) KAS-FFC-SSC Sp800-56Ar3: (A2906) KDF TLS: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) Safe Primes Key Generation: (A2906) Safe Primes Key Verification: (A2906) KAS-FFC-KeyGen (IPSec/IKE) CKG KAS-KeyGen KAS FFC keygen used in IPSec/IKEv2 service Strength:2048 bit keys providing 112 bits of encryption strength Counter DRBG: (A2906) CKG: () KAS-FFC-KeyGen (SSH) CKG KAS-KeyGen KAS FFC keygen used in SSHv2 service Strength:2048- bit key providing 112 bits of encryption strength Counter DRBG: (A2906) CKG: () KAS-FFC-KeyGen (TLSv1.2) CKG KAS-KeyGen KAS FFC keygen used in TLSv1.2 service Strength:2048- bit key providing 112 bits of encryption strength Counter DRBG: (A2906) CKG: () KTS (SSHv2 with AES and HMAC) KTS-Wrap KTS via SSHv2 service by using AES and HMAC Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology providing between 128 and 256 bits of security strength AES-CBC: (A2906) HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) Page 17 of 80 Name Type Description Properties Algorithms KTS (SSHv2 with AES-GCM) KTS-Wrap KTS via SSHv2 service by using AES- GCM Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology providing between 128 and 256 bits of security strength AES-GCM: (A2906) AES-CBC: (A2906) KTS (TLSv1.2 with AES and HMAC) KTS-Wrap KTS via TLSv1.2 service by using AES and HMAC Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology providing between 128 and 256 bits of security strength AES-CBC: (A2906) HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) KTS (TLSv1.2 with AES-GCM) KTS-Wrap KTS via TLSv1.2 service by using AES- GCM Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology providing between 128 and 256 bits of security strength AES-GCM: (A2906) AES-CBC: (A2906) Session Authentication (IPSec/IKE) MAC IPSec/IKE session authentication HMAC-SHA2- 256: (A2906) HMAC-SHA-1: (A2906) HMAC-SHA2- 512: (A2906) SHA2-256: (A2906) SHA-1: (A2906) Page 18 of 80 Name Type Description Properties Algorithms SHA2-512: (A2906) Session Authentication (SNMPv3) MAC SNMPv3 session authentication HMAC-SHA-1: (A2906) HMAC-SHA2- 224: (A2906) SHA-1: (A2906) SHA2-224: (A2906) Session Authentication (SSHv2) MAC SSHv2 session authentication HMAC-SHA-1: (A2906) HMAC-SHA2- 256: (A2906) HMAC-SHA2- 512: (A2906) SHA-1: (A2906) SHA2-256: (A2906) SHA2-512: (A2906) Session Authentication (TLSv1.2) MAC TLSv1.2 session authentication HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) Session Encryption/Decryption (IPSec/IKE) BC-Auth BC-UnAuth IPSec/IKE session protection AES-CBC: (A2906) AES-GCM: (A2906) Session Encryption/Decryption (SNMPv3) BC-UnAuth SNMPv3 session protection AES-CFB128: (A2906) Session Encryption/Decryption (SSH) BC-Auth BC-UnAuth SSHv2 session protection AES-CBC: (A2906) AES-CTR: (A2906) AES-GCM: (A2906) Session Encryption/Decryption (TLSv1.2) BC-Auth BC-UnAuth TLSv1.2 session protection AES-CBC: (A2906) AES-GCM: (A2906) Page 19 of 80 Name Type Description Properties Algorithms SNMPv3 Keying Materials Development KAS-135KDF SNMPv3 session keying materials, used to derive SNMPv3 session keys KDF SNMP: (A2906) SHA-1: (A2906) SSH ECDSA KeyGen AsymKeyPair- KeyGen CKG ECDSA KeyGen for SSHv2 ECDSA KeyGen (FIPS186-4): (A2906) Counter DRBG: (A2906) CKG: () SSH ECDSA SigGen DigSig-SigGen ECDSA SigGen for SSHv2 SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) ECDSA SigGen (FIPS186-4): (A2906) SSH ECDSA SigVer DigSig-SigVer ECDSA SigVer for SSHv2 SHA-1: (A2906) SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) ECDSA SigVer (FIPS186-4): (A2906) ECDSA KeyVer (FIPS186-4): (A2906) SSH RSA KeyGen AsymKeyPair- KeyGen CKG RSA KeyGen for SSHv2 RSA KeyGen (FIPS186-4): (A2906) Counter DRBG: Page 20 of 80 Name Type Description Properties Algorithms (A2906) CKG: () SSH RSA SigGen DigSig-SigGen ECDSA SigGen for SSHv2 SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) ECDSA SigGen (FIPS186-4): (A2906) SSH RSA SigVer DigSig-SigVer RSA SigVer for SSHv2 SHA-1: (A2906) SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) RSA SigVer (FIPS186-4): (A2906) SSHv2 Keying Materials Development KAS-135KDF SSHv2 session keying materials, used to derive SSHv2 session keys. SHA-1: (A2906) SHA2-256: (A2906) SHA2-512: (A2906) KDF SSH: (A2906) TLS ECDSA KeyGen AsymKeyPair- KeyGen CKG ECDSA KeyGen for TLSv1.2 ECDSA KeyGen (FIPS186-4): (A2906) Counter DRBG: (A2906) CKG: () TLS ECDSA SigGen DigSig-SigGen ECDSA SigGen for TLSv1.2 SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) Page 21 of 80 Name Type Description Properties Algorithms SHA2-512: (A2906) ECDSA SigGen (FIPS186-4): (A2906) TLS ECDSA SigVer DigSig-SigVer ECDSA SigVer for TLSv1.2 SHA-1: (A2906) SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) ECDSA SigVer (FIPS186-4): (A2906) ECDSA KeyVer (FIPS186-4): (A2906) TLS RSA KeyGen AsymKeyPair- KeyGen CKG RSA KeyGen for TLSv1.2 RSA KeyGen (FIPS186-4): (A2906) Counter DRBG: (A2906) CKG: () TLS RSA SigGen DigSig-SigGen RSA SigGen for TLSv1.2 SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) SHA2-512: (A2906) RSA SigGen (FIPS186-4): (A2906) TLS RSA SigVer DigSig-SigVer RSA SigVer for TLSv1.2 SHA-1: (A2906) SHA2-224: (A2906) SHA2-256: (A2906) SHA2-384: Page 22 of 80 Name Type Description Properties Algorithms (A2906) SHA2-512: (A2906) TLSv1.2 Keying Materials Development KAS-135KDF TLSv1.2 session keying materials, used to derive TLSv1.2 session keys HMAC-SHA2- 256: (A2906) HMAC-SHA2- 384: (A2906) KDF TLS: (A2906) SHA2-256: (A2906) SHA2-384: (A2906) Table 6: Security Function Implementations 2.7 Algorithm Specific Information 2.7.1 IG C.H Conformance GCM is used in the context of TLS, IPsec/IKEv2, and SSH: ● For TLS, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with SP800-52 and in accordance with Section 4 of RFC 5288 for TLS key establishment, and ensures when the nonce_explicit part of the IV exhausts all possible values for a given session key, that a new TLS handshake is initiated per sections 7.4.1.1 and 7.4.1.2 of RFC 5246. During operational testing, the module was tested against an independent version of TLS and found to behave correctly. • From this RFC 5288, the GCM cipher suites in use are TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, and TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. ● For IPsec/IKEv2, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with RFCs 4106 and 7296 (RFC 5282 is not applicable, as the module does not use GCM within IKEv2 itself), and ensures when the module exhausts all possible values for a given session key that this triggers a rekey condition. During operational testing, the module was tested against an independent version of IPsec with IKEv2 and found to behave correctly. ● For SSH, the module meets Scenario 1 of IG C.H. The module conforms to RFCs 4252, 4253, and 5647. The fixed field is 4-byte in length and is derived using the SSH KDF; this ensures the fixed field is unique for any given GCM session. The invocation field is 8-byte in length and is incremented for each invocation of GCM; this prevents the IV from repeating until the entire invocation field space of 264 is exhausted, which can take hundreds of years. (In “Approved Mode” SSH rekey is automatically configured at 1 GB of data or 1 hour, whichever comes first.) Page 23 of 80 In all the above cases, the nonce_explicit is always generated deterministically. AES GCM keys are zeroized when the module is power-cycled. For each new TLS or SSH session, a new AES GCM key is established. 2.7.2 IG C.F Conformance The module utilizes Approved modulus sizes 2048, 3072, and 4096 bits for RSA signatures. This functionality has been CAVP tested as noted above. The minimum number of Miller Rabin tests for each modulus size is implemented according to Table C.2 of FIPS 186-4. For modulus size 4096, the module implements the largest number of Miller-Rabin tests shown in Table C.2. RSA SigVer is CAVP tested for all three supported modulus sizes as noted above. The module does not perform FIPS 186-2 SigVer. All supported modulus sizes are CAVP testable and tested as noted above. The module does not implement RSA key transport in the Approved mode. 2.8 RBG and Entropy Cert Number Vendor Name E130 Palo Alto Networks, Inc. E64 Palo Alto Networks, Inc. Table 7: Entropy Certificates Name Type Operational Environment Sample Size Entropy per Sample Conditioning Component Palo Alto Networks DRNG Entropy Source - Ice Lake 28- Core Die with FCLGA4189 Package Physical Intel Corporation Intel(R) Xeon(R) Ice Lake-28 FCLGA4189 128 128 A2518 (AES- CBC-MAC) Palo Alto Networks RTC Entropy Source Non- Physical WildFire 10 on Intel Xeon E5- 2620 for WF-500 80 bits 40.5555 bits Table 8: Entropy Sources The Intel DRNG utilizes a vetted conditioner (AES-CBC-MAC) that outputs full entropy (128-bits per 128-bits of output). Upon boot, the AES-256 Counter DRBG (security strength of 256-bits) requests 384-bits from the Intel DRNG entropy source. Therefore, it is fully seeded with 384 bits of entropy. The Palo Alto Networks RTC Entropy Source is estimated to provide a minimum of 0.5069 bits per bit of output. Upon boot, the AES-256 Counter DRBG (security strength of 256-bits) requests 384-bits from the entropy source. Therefore, the DRBG is initially seeded with at least 194 bits of entropy upon initial instantiation of the DRBG. This is greater than the 112-bit minimum, but less than the maximum security strength of the CTR DRBG. Therefore, the Page 24 of 80 module requires the caveat "The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.” 2.9 Key Generation The module implements CKG where seeds used for asymmetric key pair generation are produced using the unmodified/direct output of the DRBG. 2.10 Key Establishment The module provides the following key/SSP establishment services in the Approved mode of operation: ● KAS-ECC Shared Secret Computation o The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (1) with KAS-ECC shared secret computation. The shared secret computation provides between 128 and 256 bits of encryption strength. ● KAS-FFC Shared Secret Computation o The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (1) with KAS-FFC shared secret computation. The shared secret computation provides between 112 and 150 bits of encryption strength. 2.11 Industry Protocols ● TLS 1.2 ● SSHv2 ● SNMPv3 ● IPSec and IKEv2 *Note: No parts of these protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP . 3 Cryptographic Module Interfaces 3.1 Ports and Interfaces Physical Port Logical Interface(s) Data That Passes LED Status Output Module status via LED indicators Power Power N/A RJ45 Console Status Output Self-test output RJ45 Ethernet Data Input Data Output TLS, IPSec or SSH Page 25 of 80 Physical Port Logical Interface(s) Data That Passes Control Input Status Output SFP+ (WF-500-B) Data Input Data Output Control Input Status Output TLS Table 9: Ports and Interfaces 4 Roles, Services, and Authentication 4.1 Authentication Methods Method Name Description Security Mechanism Strength Each Attempt Strength per Minute RSA- Based Certificate The modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits Single-Factor Cryptographic Software With a minimum modulus size of 2048, the probability that a random attempt will succeed is 1/(2^112). The probability of successfully authenticating to the module within a one minute period is 288,000,000/(2112). The module supports at most 4,800,000 new sessions per second. ECDSA- Based Certificate The modules support ECDSA public- key based authentication mechanism using a minimum ECDSA curve of P-256 Single-Factor Cryptographic Software With a minimum curve of P- 256, the probability that a random attempt will succeed is 1/(2^128). The probability of successfully authenticating to the module within a one minute period is 288,000,000/(2112). The module supports at most 4,800,000 new sessions per second. Password Password based authentication Memorized Secret (Unique Username/password) The minimum length is eight (8) characters (95 possible characters). The probability that a random attempt will succeed or a The probability of successfully authenticating to the module within one minute is 10/(95^8). The firewall's configuration supports at most ten failed attempts to Page 26 of 80 Method Name Description Security Mechanism Strength Each Attempt Strength per Minute false acceptance will occur is 1/(95^8). authenticate in a one- minute period. Table 10: Authentication Methods 4.2 Roles Name Type Operator Type Authentication Methods Crypto Officer Identity CO RSA-Based Certificate ECDSA-Based Certificate Password User Identity User RSA-Based Certificate ECDSA-Based Certificate Password Table 11: Roles 4.3 Approved Services Name Description Indicator Inputs Outputs Security Functions SSP Access Check Status Provides status information of the module Configuration/ System Logs Initiate show status comman d Module provides status output of module None Crypto Officer - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: E - Entropy Input String: G,E - RSA Private Keys: E Page 27 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,E,R,W, Z - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,E,R,W, Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Page 28 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z User - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: E - Entropy Input String: G,E - RSA Private Keys: E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,E,R,W, Z - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Page 29 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,E,R,W, Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Data Analysis Manage ment Networking parameter configuration, logging configuration, and other non-security relevant configuration Configuration, System Logs Input configur ations for other setup functions Module uses configur ation KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) Crypto Officer - CO, User Password: G,E,W - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Page 30 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/De cryption (SSH) Session Encryption/De cryption (TLSv1.2) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA Keys: G,W,E - Entropy Input String: G,E - RSA Private Keys: G,W,E - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,E,R,W, Z - SSH Host Public Key: G,R,E,W - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Page 31 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer SSHv2 Keying Materials Development TLSv1.2 Keying Materials Development Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,E,R,W, Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Firmwar e Update Provides a method to update the firmware of the module Configuration/ System Logs Uploadin g new firmware Status of the updated firmware installati on Firmware Load Test Crypto Officer - Public key for firmware content load test: E IKE/IPse c configur ation Configuration/ System Configuration/ System Logs Initialize VPN connecti on Confirm ation of service via System Logs IPSec/IKE ECDSA KeyGen IPSec/IKE ECDSA SigGen IPSec/IKE ECDSA SigVer IPSec/IKE RSA KeyGen IPSec/IKE RSA SigGen IPSec/IKE RSA SigVer Crypto Officer - CA Certificate s: G,R,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: Page 32 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access IPSec/IKEv2 Keying Materials Development KAS-ECC (IPSec/IKE) KAS-ECC- KeyGen (IPSec/IKE) KAS-FFC (IPSec/IKE) KAS-FFC- KeyGen (IPSec/IKE) Session Authentication (IPSec/IKE) Session Encryption/De cryption (IPSec/IKE) G,W,E - ECDSA Public Keys: G,R,W,E - Entropy Input String: G,E - IPSec/IKE Authentica tion Keys: G,E,Z - IPSec/IKE DHE/ECD HE Private Compone nts: G,E,Z - IPSec/IKE DHE/ECD HE Public Compone nts: G,R,W,E, Z - IPSec/IKE Session Keys: G,E,Z - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E Self- Tests Initiates self- tests and integrity test System Logs Self-test comman d or rebootin g the module Status of the self- tests None Crypto Officer - Firmware integrity verificatio n key: R Page 33 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Show Status (LEDs) Provides status of the module LEDs N/A Status of the module via LEDs None Unauthent icated Show Version Shows the version of the module Version displayed via System Logs / CLI / UI Input comman d for version Module displays version informati on None Crypto Officer System Audit Allows review of limited configuration and system status via logs. Provides no configuration commit capability. Configuration/ System Logs View the System Logs via CLI System Logs None Crypto Officer - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: E - Entropy Input String: G,E - RSA Private Keys: E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Session Authentica tion Keys: Page 34 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access G,E,Z - SSH Session Encryption Keys: G,E,Z - SSH Shared Secret: G,E,Z System Configur ation Manage ment Configuring and managing cryptographic parameters and setting,modify ing security policy, including creating User accounts and additional CO accounts Configuration/ System Logs Input configur ation for various cryptogr aphic functions Module uses the configur ation for cryptogr aphic purpose s KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Crypto Officer - CA Certificate s: G,R,E,W - CO, User Password: G,E,W - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Keys: G,R,E,W - Entropy Input String: G,E - Protocol Secrets: W,E - Public key for firmware content load test: W,E - RSA Private Page 35 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Authentication (TLSv1.2) Session Encryption/De cryption (SNMPv3) Session Encryption/De cryption (SSH) Session Encryption/De cryption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLSv1.2 Keying Keys: G,W,E - RSA Public Keys: G,R,E,W - SNMPv3 Authentica tion Key: G,E,Z - SNMPv3 Authentica tion Secret: W,E - SNMPv3 Privacy Secret: W,E - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,E,R,W, Z - SSH Host Public Key: G,R,E,W - SSH Session Authentica tion Keys: Page 36 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Materials Development G,E,Z - SSH Session Encryption Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,E,R,W, Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z System Operatio nal Manage ment Configuring and managing networking parameter configuration, logging configuration, and other non-security Configuration/ System Logs Input configur ation for various cryptogr aphic functions Module uses the configur ation for cryptogr aphic purpose s KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) Crypto Officer - CA Certificate s: G,R,E,W - CO, User Password: G,E,W Page 37 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access relevant configuration via CLI KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/De cryption (SNMPv3) Session Encryption/De cryption (SSH) Session Encryption/De cryption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen - DRBG Key: G,W,E - DRBG Seed: G,E - DRBG V: G,W,E - ECDSA Private Keys: G,W,E - ECDSA Public Keys: G,R,E,W - Entropy Input String: G,E - Protocol Secrets: W,E - Public key for firmware content load test: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,E,W - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Page 38 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLSv1.2 Keying Materials Development Compone nts: G,E,R,W, Z - SSH Host Public Key: G,R,E,W - SSH Session Authentica tion Keys: G,E,Z - SSH Session Encryption Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,E,R,W, Z - TLS Encryption Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Page 39 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Master Secret: G,E,Z Zeroize Zeroizes all keys in the module Zeroization indicator Initiating zeroizati on comman d Status of the zeroizati on process None Crypto Officer - CA Certificate s: Z - CO, User Password: Z - DRBG Key: Z - DRBG Seed: Z - DRBG V: Z - ECDSA Private Keys: Z - ECDSA Public Keys: Z - Entropy Input String: Z - Firmware integrity verificatio n key: Z - IPSec/IKE Authentica tion Keys: Z - IPSec/IKE DHE/ECD HE Private Compone nts: Z - IPSec/IKE DHE/ECD HE Public Compone Page 40 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access nts: Z - IPSec/IKE Session Keys: Z - Protocol Secrets: Z - Public key for firmware content load test: Z - RSA Private Keys: Z - RSA Public Keys: Z - SNMPv3 Authentica tion Key: Z - SNMPv3 Authentica tion Secret: Z - SNMPv3 Privacy Secret: Z - SNMPv3 Session Key: Z - SSH Client Public Key: Z - SSH DHE/ECD HE Private Compone nts: Z - SSH DHE/ECD HE Public Compone nts: Z - SSH Page 41 of 80 Name Description Indicator Inputs Outputs Security Functions SSP Access Host Public Key: Z - SSH Session Authentica tion Keys: Z - SSH Session Encryption Keys: Z - SSH Shared Secret: Z - TLS DHE/ECD HE Private Compone nts: Z - TLS DHE/ECD HE Public Compone nts: Z - TLS Encryption Keys: Z - TLS HMAC Keys: Z - TLS Master Secret: Z - TLS Pre- Master Secret: Z Table 12: Approved Services 4.4 Non-Approved Services N/A for this module. Page 42 of 80 4.5 External Software/Firmware Loaded The module supports the firmware load test by using RSA 2048 bits with SHA2-256 (RSA Cert. #A2906) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate into the module before loading any firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. 5 Software/Firmware Security 5.1 Integrity Techniques The module performs the Firmware Integrity test by using HMAC-SHA2-256 and ECDSA signature verification (HMAC and ECDSA Cert. #A2906) during the Pre-Operational Self-Test. In addition, the module also conducts the firmware load test by using the Public Key for Firmware Load Test (RSA 2048 with SHA2-256, Cert. #A2906) for the new validated firmware to be uploaded into the module via the System Operational Management service. The Firmware Integrity Verification Key and Public Key for Firmware Load Test used for the Firmware Integrity and Firmware Load test, respectively, are generated externally and delivered as part of the module firmware image. The pre-operational self-tests can be initiated by power cycling the module. When this is performed, the module automatically runs the cryptographic algorithm self-tests in addition to the pre-operational firmware integrity test. The module’s executable code is in the form of the compiled firmware image loaded onto the module. 5.2 Initiate on Demand The pre-operational self-tests can be initiated by power cycling the module. When this is performed, the module automatically runs the cryptographic algorithm self-tests in addition to the pre-operational firmware integrity test. 6 Operational Environment 6.1 Operational Environment Type and Requirements The FIPS 140-3 Area 6 Operational Environment requirements are not applicable because the module contains a limited operational environment. The operational environment is limited since the module includes a firmware load service to support necessary updates. New firmware versions within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. Type of Operational Environment: Limited Page 43 of 80 7 Physical Security 7.1 Mechanisms and Actions Required Mechanism Inspection Frequency Inspection Guidance Tamper-Evident Seals 30 days Verify integrity of tamper-evident seals in the locations specified in this section. Front and Rear Opacity Shields 30 days Verify that the front and rear opacity shields have not been deformed from their original shape, thereby reducing their effectiveness. Vent Overlays 30 days Verify that the vent overlays have not been removed or deformed. All edges should maintain strong adhesion characteristics. Table 13: Mechanisms and Actions Required The multi-chip standalone module is production quality and contains standard passivation. Chip components are protected by an opaque enclosure. There are tamper-evident seals that are applied on the module by the Crypto-Officer, and any unused seals are to be controlled by the Crypto-Officer. The Crypto-Officer must ensure that the module surface is clean and dry before applying the seals. The seals prevent removal of the opaque enclosure without evidence, which should be inspected by the Crypto-Officer every 30 days for evidence of tampering. If the seals or opacity shields show evidence of tamper, the Crypto-Officer should assume that the module has been compromised and contact Customer Support. Note: For ordering information, physical kit part numbers and version. Opacity shields are included in the physical kits. 7.2 User Placed Tamper Seals Number: WF-500 Tamper Seal Installation (12 Seals) Placement: WF-500 Tamper Seal Installation (12 Seals) 1. Remove the two pull handles and front modules on the left and right side of the appliance by removing the three (3) screws located behind each handle/module. There is no need to disconnect the LED circuit board attached to the end of the ribbon cable. Retain these screws for Step 2. Page 44 of 80 2. Attach the left and right front cover brackets to the appliance using the six (6) screws that were removed in Step 1. First attach the brackets using the bottom screws (one (1) on each side) as shown in Figure 6, ensuring that you feed the ribbon cable and LED circuit board through the left bracket. Replace the front modules and secure them using the middle and top screws on each side as shown in Figure 7. Page 45 of 80 3. Secure the front opacity shield to the right and left front brackets that you installed in Step 2. Use two (2) screws (provided) on each side. Page 46 of 80 Page 47 of 80 4. Attach the rear opacity shield tray to the appliance. appliance and use these screws to secure the rear opacity shield tray. First, remove the two (2) screws (shown in Figure 10) from the Note: Install the back cables (power cords and network/management cables) because you will not be able to access these ports after the next step. 5. Place the rear opacity shield on top of the rear opacity shield tray ensuring that you run the cables through the opening at the bottom. Secure the opacity shields with two (2) screws (provided) on each side. Page 48 of 80 6. Cover the vent openings as shown in Figure 12 by applying one (1) overlay tamper-evident seal over the left side vent and one overlay tamper-evident seal over the right-side vent. Each overlay requires two (2) tamper-evident seals as shown in Figure 13. Also apply one (1) additional tamper-evident seal as shown in Figure 13, #5. Page 49 of 80 7. Attach the rail kit to the appliance as shown in Figure 14 and then add three (3) tamper- evident seals to the bottom of the appliance as shown in Figure 15. One (1) tamper-evident seal #6 prevents tampering of the front opacity shield connected to the bottom of the appliance and two (2) tamper-evident seals #7 and #8 wrap around the upper and lower rear opacity shields to prevent tampering of the rear opacity shields. Page 50 of 80 8. Place four (4) tamper seals on the top of the appliance. Two (2) tamper seals (#9 and #11) prevent tampering of the top front and rear opacity shields and two (2) tamper seals (#10 and #12) prevents someone from attempting to access the vent overlays by sliding the rail kit. This completes the physical kit installation. Page 51 of 80 WF-500-B Tamper Seal Installation (21 Seals) 1. Replace the top cover with the physical kit top cover. a. Remove the VOID WARRANTY label and cover screws (replacement label included in the kit). Remove the Void Warranty label that covers the left side cover screw then use a Phillips-head screwdriver to remove both screws as indicated in the illustration. Simultaneously depress the two (2) release buttons on top of the cover and slide the cover toward the back of the appliance to remove it. Slide the physical kit top cover (does not have vents) on the appliance until the release buttons click. Replace the two screws that you removed from the old cover Page 52 of 80 2. Attach the physical kit front cover brackets. Remove the front pull handles by removing two (2) screws from each handle (one (1) handle on each side), insert the WF-500-B physical kit front-cover brackets under each handle, and then replace the handles and secure them using the screws that you removed. The physical kit handles have standoffs that are used to secure the front cover. Page 53 of 80 3. Attach the physical kit front cover to the front of the appliance. Slide the WF-500-B physical kit front cover over the physical kit pull handle brackets and secure the cover by turning the thumb screws clockwise (one thumb screw on each side). Install a tamper-evident seal on the back of the appliance. This is seal #13 in the WF-500-B Figure 19. You need to install this seal before you install the WF-500-B physical kit back cover. Page 54 of 80 Attach the physical kit back cover to the back of the appliance. Slide the back cover onto the back of the appliance and turn the two (2) thumb screws clockwise until tight (one (1) screw on each side) to secure the cover. Apply a tamper-evident seal to each location shown in the following WF-500-B illustrations below. Also install the overlay stickers to cover vent openings (two (2) stickers on each side). You then install tamper-evident seals over the overlay stickers. Apply two (2) tamper-evident seals on the back side of the right rack handle (see seals #18 and #19 on the left side in Figure 19). Apply two (2) tamper-evident seals on the power supplies (see seals #11 and #12 with rear inset of Figure 19). Before you apply the tamper-evident seals, ensure that the appliance and physical kit surfaces are clean and dry. Firmly press one (1) seal on each of the locations shown in the illustrations. Avoid touching the seals for at least 24 hours to allow time for the seals to properly adhere to the appliance and physical kit surfaces. Page 55 of 80 8 Non-Invasive Security N/A Page 56 of 80 9 Sensitive Security Parameters Management 9.1 Storage Areas Storage Area Name Description Persistence Type HDD Non-Volatile Memory Static RAM Volatile Memory Dynamic Table 14: Storage Areas 9.2 SSP Input-Output Methods Name From To Format Type Distributio n Type Entry Type SFI or Algorith m Module Public Key Output HDD External (Outside of the Module's Boundary ) Plaintext Automated Electroni c Password/Secret Input via SSHv2 encrypted by AES and HMAC External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (SSHv2 with AES and HMAC) Password/Secret Input via SSHv2 encrypted by AES-GCM External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (SSHv2 with AES- GCM) Password/Secret Input via TLSv1.2 encrypted by AES and HMAC External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (TLSv1.2 with AES and HMAC) Password/Secret Input via TLSv1.2encrypte d by AES-GCM External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (TLSv1.2 with AES- GCM) Peer Public Key Input External (outside HDD Plaintext Automated Electroni c Page 57 of 80 Name From To Format Type Distributio n Type Entry Type SFI or Algorith m of module's boundary ) Table 15: SSP Input-Output Methods 9.3 SSP Zeroization Methods Zeroization Method Description Rationale Operator Initiation Power Cycle/Session Termination Operator powers the module off or session terminates, and the module's memory is overwritten with a random pattern. Powering off the module or terminating the session will erase all SSPs stored in the RAM of the module and make them non- retrievable. Command via CLI by unplugging module Zeroization Command CO issues zeroization service SSPs are zeroized by overwriting the memory with a random pattern. The zeroization command will erase all SSPs stored in the RAM or in the Flash of the module and make them non-retrievable. Entering into maintenance mode and selecting Factory Reset Table 16: SSP Zeroization Methods 9.4 SSPs Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By CA Certificate s ECDSA/RSA Public key - Used to trust a root CA intermediate CA and leaf /end entity certificates (RSA 2048, 3072, and 4096 bits) (ECDSA P- 256, P-384, and P-521) 2048 bits, 3072 bits, 4096 bits; 256 bits, 384 bits, 521 bits - 112 bits,128 bits, 150 Public Key - PSP IPSec/IK E ECDSA KeyGen IPSec/IK E RSA KeyGen TLS ECDSA KeyGen TLS RSA KeyGen IPSec/IKE ECDSA SigVer IPSec/IKE RSA SigVer TLS ECDSA SigVer TLS RSA SigVer Page 58 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By bits; 128 bits,192 bits, 256 bits CO, User Password Authenticatio n string with a minimum length of eight (8) characters. 8 charact ers minimu m - N/A Authentica tion Data - CSP External DRBG Key AES 256 CTR DRBG state Key used in the generation of a random values 128 bits - 256 bits DRBG Key - CSP Entropy as per SP 800- 90B Counter DRBG (A2906) DRBG Seed DRBG seed coming from the entropy source Seed length = 384 bits 384 bits - 384 bits (E64), 194 bits (E130) DRBG Seed - CSP Entropy as per SP 800- 90B Counter DRBG (A2906) DRBG V AES 256 CTR DRBG state V used in the generation of a random values 128 bits - 128 bits DRBG Internal State V value - CSP Entropy as per SP 800- 90B Counter DRBG (A2906) ECDSA Private Keys ECDSA Private key for generation of signatures and authentication (P-256, P- 384, or P- 521) 256 - 521 bits - 128 - 256 bits Private Key - CSP IPSec/IK E ECDSA KeyGen SSH ECDSA KeyGen TLS ECDSA KeyGen IPSec/IKE ECDSA SigGen SSH ECDSA SigGen TLS ECDSA SigGen ECDSA Public Keys ECDSA public keys managed as certificates for the verification of signatures, 256 - 521 bits - 128 - 256 bits Public Key - PSP IPSec/IK E ECDSA KeyGen SSH ECDSA KeyGen TLS IPSec/IKE ECDSA SigVer SSH ECDSA SigVer TLS ECDSA SigVer Page 59 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By establishment of TLS, operator authentication and peer authentication . (ECDSA P- 256, P-384, or P-521) ECDSA KeyGen Entropy Input String Entropy input string coming from the entropy source Input length = 384 bits 384 bits - 384 bits (E64), 194 bits (E130) DRBG - CSP Entropy as per SP 800- 90B Counter DRBG (A2906) Firmware integrity verification key Used to check the integrity of all firmware code (HMAC-SHA- 256 and ECDSA P- 256) (Note: This is not considered an SSP) 128 bits - 128 bits Public Key - Neither IPSec/IKE Authentica tion Keys Used for authentication of session (HMAC-SHA- 1/256/384/51 2) 160 - 512 bits - 128 - 256 bits Session key - CSP IPSec/IK Ev2 Keying Materials Develop ment KAS- ECC (IPSec/IK E) KAS- FFC (IPSec/IK E) Session Authentication (IPSec/IKE) IPSec/IKE DHE/ECD HE Private Compone nts Diffie-Hellman or EC Diffie- Hellman private component used in key establishment (DHE MODP- 2048, ECDHE P-256, P-384) 2048 bits; 256 - 384 bits - 112 bits; 128 - 192 bits Private Key - CSP KAS- ECC- KeyGen (IPSec/IK E) KAS- FFC- KeyGen (IPSec/IK E) IPSec/IKEv2 Keying Materials Development Page 60 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By IPSec/IKE DHE/ECD HE Public Compone nts Diffie-Hellman or EC Diffie- Hellman public component used in key agreement (DHE MODP- 2048, ECDHE P-256, P-384) 2048 bits; 256 - 384 bits - 112 bits; 128 - 192 bits Public Key - PSP KAS- ECC- KeyGen (IPSec/IK E) KAS- FFC- KeyGen (IPSec/IK E) IPSec/IKEv2 Keying Materials Development IPSec/IKE Session Keys Used to encrypt remote access sessions utilizing IPSec. (AES- CBC or AES- GCM) 128 - 256 bits - 128 - 256 bits Session Key - CSP KAS- ECC (IPSec/IK E) KAS- FFC (IPSec/IK E) Session Encryption/Decr yption (IPSec/IKE) Protocol Secrets Secrets used by RADIUS or TACACS+ (8 characters minimum) 8 charact ers minimu m - N/A Authentica tion Data - CSP Public key for firmware content load test Used to authenticate firmware and content to be installed on the firewall (RSA 2048 with SHA- 256) 2048 bits - 112 bits Public Key - PSP Pre- Loaded Firmware Load Test RSA Private Keys RSA Private keys for generation of signatures, authentication or key establishment . (RSA 2048, 3072, or 4096-bit) 2048 - 4096 bits - 112 - 152 bits Private Key - CSP IPSec/IK E RSA KeyGen SSH RSA KeyGen TLS RSA KeyGen TLS RSA SigGen RSA Public Keys RSA public keys managed as 2048 - 4096 bits - Public Key - PSP IPSec/IK E RSA KeyGen TLS RSA SigVer Page 61 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By certificates for the verification of signatures, establishment of TLS, operator authentication and peer authentication . (RSA 2048, 3072, or 4096-bit) 112 - 152 bits SSH RSA KeyGen TLS RSA KeyGen SNMPv3 Authentica tion Key HMAC-SHA- 1/224/256/38 4/512 Authenticatio n protocol key (160 bits) 160 - 512 bits - 128 - 256 bits Session Key - CSP SNMPv3 Keying Materials Develop ment Session Authentication (SNMPv3) SNMPv3 Authentica tion Secret Used to support SNMPv3 services (Minimum 8 characters) 8 charact ers minimu m - N/A Authentica tion Key - CSP SNMPv3 Keying Materials Development SNMPv3 Privacy Secret Used to support SNMPv3 services (Minimum 8 characters) 8 charact ers minimu m - N/A Authentica tion Key - CSP SNMPv3 Keying Materials Development SNMPv3 Session Key Privacy protocol encryption key (AES 128/192/256 CFB) 128 - 256 bits - 128 - 256 bits Session Key - CSP SNMPv3 Keying Materials Develop ment Session Encryption/Decr yption (SNMPv3) SSH Client Public Key Public RSA key used to authenticate client. (RSA 2048, 3072, and 4096 bits) 2048 - 4096 bits - 112 - 152 bits Public Key - PSP SSH RSA SigVer Page 62 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By SSH DHE/ECD HE Private Compone nts Diffie Hellman or EC Diffie- Hellman private (DH Group 14, ECDH P-256, ECDH P-384, ECDH P-521) 2048 bits; 256 - 521 bits - 112 bits; 128 - 256 bits Private Key - CSP KAS- ECC- KeyGen (SSH) KAS- FFC- KeyGen (SSH) SSHv2 Keying Materials Development SSH DHE/ECD HE Public Compone nts Diffie Hellman or EC Diffie- Hellman public component (DH Group 14, ECDH P- 256, ECDH P-384, ECDH P-521) 2048 bits; 256 - 521 bits - 112 bits; 128 - 256 bits Public Key - PSP KAS- ECC- KeyGen (SSH) KAS- FFC- KeyGen (SSH) SSHv2 Keying Materials Development SSH Host Public Key SSH Host Public Key (RSA 2048, RSA 3072, RSA 4096, ECDSA P- 256, P-384, or P-521) 2048 - 4096 bits; 256 - 521 bits - 112 - 152 bits (RSA) 128 - 256 bits (ECDS A) Public Key - PSP SSH ECDSA KeyGen SSH RSA KeyGen SSH RSA SigVer SSH ECDSA SigVer SSH Session Authentica tion Keys Authenticatio n keys used in all SSH connections to the security module's command line interface (HMAC-SHA- 1, HMAC- SHA2-256, HMAC-SHA2- 512) (160, 256, 512 bits) 160 - 512 bits - 128 - 256 bits Session Key - CSP KAS- ECC (SSH) KAS- FFC (SSH) Session Authentication (SSHv2) SSH Session Used in all SSH connections 128 - 256 bits Session Key - CSP KAS- ECC (SSH) Session Encryption/Decr yption (SSH) Page 63 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By Encryption Keys to the security module's command line interface. (128, 192, or 256 bits: AES CBC or CTR) (128 or 256 bits: AES GCM) - 128 - 256 bits KAS- FFC (SSH) SSH Shared Secret Shared secret used in SSH connections (DH MODP- 2048, ECDH P- 256/384/521) 2048 bits; 256 - 521 bits - 112 bits; 128 - 256 bits Shared Secret - CSP KAS- ECC (SSH) KAS- FFC (SSH) Session Encryption/Decr yption (SSH) TLS DHE/ECD HE Private Compone nts Ephemeral Diffie-Hellman private FFC or EC component used in TLS (DHE 2048, ECDHE P- 256, P-384, P-521) 2048 bits; 256 - 521 bits - 112 bits; 128 - 256 bits Private Key - CSP KAS- ECC- KeyGen (TLSv1.2) KAS- FFC- KeyGen (TLSv1.2) TLSv1.2 Keying Materials Development TLS DHE/ECD HE Public Compone nts Diffie_Hellma n or EC Diffie- Hellman Ephemeral values used in key agreement (DHE 2048, ECDHE P- 256, P-384, P-521) 2048 bits; 256 - 521 bits - 112 bits; 128 - 256 bits Public Key - PSP KAS- ECC- KeyGen (TLSv1.2) KAS- FFC- KeyGen (TLSv1.2) TLSv1.2 Keying Materials Development TLS Encryption Keys AES (128 or 256 bit) keys used in TLS connections (GCM; CBC) 128 - 256 bits - 128 - 256 bits Session Key - CSP KAS- ECC (TLSv1.2 ) KAS- FFC (TLSv1.2 ) Session Encryption/Decr yption (TLSv1.2) Page 64 of 80 Name Description Size - Strengt h Type - Category Generate d By Establis hed By Used By TLS HMAC Keys HMAC keys used in TLS connections (HMAC- SHA2- 256/384) ( 256, 384 bits) 256 - 384 bits - 256 bits Session Key - CSP KAS- ECC (TLSv1.2 ) KAS- FFC (TLSv1.2 ) Session Authentication (TLSv1.2) TLS Master Secret Secret value used to derive the TLS session keys 384 bits - N/A Master Secret - CSP TLSv1.2 Keying Materials Develop ment KAS- ECC (TLSv1.2 ) KAS- FFC (TLSv1.2 ) TLSv1.2 Keying Materials Development TLS Pre- Master Secret Secret value used to derive the TLS Master Secret along with client and server random nonces 2048 bits; 256 bits, 384 bits, 521 bits - 112 bits; 256 bits, 384 bits, 521 bits Shared Secret - CSP KAS- ECC (TLSv1.2 ) KAS- FFC (TLSv1.2 ) TLSv1.2 Keying Materials Development Table 17: SSP Table 1 Name Input - Output Storage Storage Duration Zeroization Related SSPs CA Certificates Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Peer Public Key Input HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued or session terminati on Zeroization Command Power Cycle/Sessi on Termination RSA Private Keys:Decrypts RSA Public Keys:Encrypts ECDSA Private Keys:Decrypts ECDSA Public Keys:Encrypts Page 65 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM CO, User Password Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM HDD:Obfuscat ed N/A Zeroization Command DRBG Key RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination Entropy Input String:Paired With DRBG V:Paired With DRBG Seed RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination Entropy Input String:Paired With DRBG Key:Paired With DRBG V:Paired With DRBG V RAM:Plaintext Until session Power Cycle/Sessi Entropy Input String:Paired With Page 66 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs terminati on on Termination DRBG Key:Paired With ECDSA Private Keys Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued or session terminati on Zeroization Command Power Cycle/Sessi on Termination ECDSA Public Keys:Paired With ECDSA Public Keys Module Public Key Output Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Peer Public Key Input Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command ECDSA Private Keys:Paired With Page 67 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs encrypted by AES-GCM Entropy Input String RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination DRBG Seed:Paired With DRBG Key:Paired With DRBG V:Paired With Firmware integrity verification key HDD:Plaintext N/A N/A IPSec/IKE Authenticati on Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination IPSec/IKE DHE/ECDH E Private Component s RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination IPSec/IKE DHE/ECDHE Public Components:Pair ed With IPSec/IKE DHE/ECDH E Public Component s RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination IPSec/IKE DHE/ECDHE Private Components:Pair ed With IPSec/IKE Session Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination Protocol Secrets Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr HDD:Plaintext N/A Zeroization Command Page 68 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs et Input via SSHv2 encrypted by AES-GCM Public key for firmware content load test HDD:Plaintext N/A N/A RSA Private Keys Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued or session terminati on Zeroization Command Power Cycle/Sessi on Termination RSA Public Keys:Paired With RSA Public Keys Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Peer Public Key Input Password/Secr et Input via TLSv1.2 encrypted by AES and HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command RSA Private Keys:Paired With Page 69 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM SNMPv3 Authenticati on Key HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command SNMPv3 Authentication Secret:Derived From SNMPv3 Privacy Secret:Derived From SNMPv3 Authenticati on Secret Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command SNMPv3 Privacy Secret Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Password/Secr et Input via HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command Page 70 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM SNMPv3 Session Key HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command Derived From SNMPv3 Authentication Secret:Derived From SNMPv3 Privacy Secret:Derived From SSH Client Public Key Password/Secr et Input via SSHv2 encrypted by AES and HMAC Password/Secr et Input via TLSv1.2encryp ted by AES- GCM Peer Public Key Input Password/Secr et Input via TLSv1.2 encrypted by AES and HMAC Password/Secr et Input via SSHv2 encrypted by AES-GCM HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command SSH DHE/ECDH E Private Component s RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination SSH DHE/ECDHE Public Components:Pair ed With SSH DHE/ECDH Module Public Key Output RAM:Plaintext Until session Power Cycle/Sessi SSH DHE/ECDHE Page 71 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs E Public Component s Peer Public Key Input terminati on on Termination Private Components:Pair ed With SSH Host Public Key HDD:Plaintext RAM:Plaintext Until zeroizati on comman d is issued Zeroization Command SSH Session Authenticati on Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination SSH DHE/ECDHE Public Components:Deri ved From SSH DHE/ECDHE Private Components:Deri ved From SSH Session Encryption Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination Derived From SSH DHE/ECDHE Public Components:Deri ved From SSH DHE/ECDHE Private Components:Deri ved From SSH Shared Secret RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination SSH DHE/ECDHE Private Components:Deri ved From SSH DHE/ECDHE Public Components:Deri ved From TLS DHE/ECDH E Private Component s RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination TLS DHE/ECDHE Public Components:Pair ed With TLS DHE/ECDH E Public Module Public Key Output RAM:Plaintext Until session Power Cycle/Sessi TLS DHE/ECDHE Private Page 72 of 80 Name Input - Output Storage Storage Duration Zeroization Related SSPs Component s Peer Public Key Input terminati on on Termination Components:Pair ed With TLS Encryption Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination TLS Master Secret:Derived From TLS HMAC Keys RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination TLS Master Secret:Derived From TLS Master Secret RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination TLS Pre-Master Secret:Derived From TLS Pre- Master Secret RAM:Plaintext Until session terminati on Power Cycle/Sessi on Termination Table 18: SSP Table 2 10 Self-Tests 10.1 Pre-Operational Self-Tests Algorithm or Test Test Properties Test Method Test Type Indicator Details ECDSA SigVer (FIPS186-4) (A2906) P-256 KAT SW/FW Integrity Self-Test successful Signature Verification HMAC-SHA2-256 (A2906) SHA2-256 KAT SW/FW Integrity Self-Test successful Keyed Checksum Table 19: Pre-Operational Self-Tests Firmware Integrity Test -Verified with HMAC-SHA2-256 and ECDSA P-256 Note: the ECDSA and HMAC-SHA2-256 KATs are performed prior to the Firmware integrity test 10.2 Conditional Self-Tests Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns AES GCM (A2906) Decrypt 256 Bits KAT CAST Self-test output messag e Decrypt After each power-on or via self-test command Page 73 of 80 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns AES GCM (A2906) Encrypt 256 Bits KAT CAST Self-test output messag e Encrypt After each power-on or via self-test command AES- ECB (A2906) Decrypt 128 Bits KAT CAST Self-test output messag e Decrypt After each power-on or via self-test command Counter DRBG (A2906) N/A KAT CAST Self-test output messag e SP 800-90Arev1 Instantiate/Generate/Res eed Known Answer Tests After each power-on or via self-test command ECDSA KeyGen (FIPS186 -4) (A2906) 256 Bit Minimum PCT PCT System log messag es ECDSA / KAS-ECC pairwise consistency test On session ECDSA SigGen (FIPS186 -4) (A2906) 256 Bits KAT CAST Self-test output messag e Sign After each power-on or via self-test command ECDSA SigVer (FIPS186 -4) (A2906) 256 Bits KAT CAST Self-test output messag e Verify After each power-on or via self-test command Firmware Load Test 2048 Bit FW Load Test SW/F W Load System log messag es Firmware load test on content load On session HMAC- SHA-1 (A2906) 160 Bits KAT CAST Self-test output messag e Keyed Hash After each power-on or via self-test command HMAC- SHA2- 224 (A2906) 224 Bits KAT CAST Self-test output messag e Keyed Hash After each power-on or via self-test command HMAC- SHA2- 256 Bits KAT CAST Self-test output Keyed Hash After each power-on or via Page 74 of 80 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns 256 (A2906) messag e self-test command HMAC- SHA2- 384 (A2906) 384 Bits KAT CAST Self-test output messag e Keyed Hash After each power-on or via self-test command HMAC- SHA2- 512 (A2906) 512 Bits KAT CAST Self-test output messag e Keyed Hash After each power-on or via self-test command RSA KeyGen (FIPS186 -4) (A2906) 2048 Bit Minimum PCT PCT System log messag es RSA pairwise consistency test On session RSA SigGen (FIPS186 -4) (A2906) 2048 Bits KAT CAST Self-test output messag e Sign After each power-on or via self-test command RSA SigVer (FIPS186 -4) (A2906) 2048 Bits KAT CAST Self-test output messag e Verify After each power-on or via self-test command Safe Primes Key Generati on (A2906) 2048 Bit Minimum PCT PCT System log messag es KAS-FCC pairwise consistency test On session SHA-1 (A2906) 160 Bits KAT CAST Self-test output messag e Hash After each power-on or via self-test command SHA2- 256 (A2906) 256 Bits KAT CAST Self-test output messag e Hash After each power-on or via self-test command SHA2- 384 (A2906) 384 Bits KAT CAST Self-test output messag e Hash After each power-on or via Page 75 of 80 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns self-test command SHA2- 512 (A2906) 512 Bits KAT CAST Self-test output messag e Hash After each power-on or via self-test command SP 800- 90B APT Health Tests on Entropy Source N/A Fault detectio n CAST Self-test output messag e Health tests done on entropy source After each power-on or via self-test command SP 800- 90B RCT Health Tests on Entropy Source N/A Fault detectio n CAST Self-test output messag e Health tests done on entropy source After each power-on or via self-test command SP 800- 135rev1 IKEv2 KDF with SHA-256 N/A KAT CAST Self-test output messag e IKEv2 with SHA-256 After each power-on or via self-test command SP 800- 135rev1 SSH KDF with SHA-256 N/A KAT CAST Self-test output messag e SSHv2 with SHA-256 After each power-on or via self-test command SP 800- 135rev1 TLS 1.2 with SHA-256 KDF N/A KAT CAST Self-test output messag e TLSv1.2 with SHA-256 After each power-on or via self-test command SP 800- 56A Rev 3 Assuranc e Tests N/A Critical Functio ns Critical Functio n System log messag es Assurance tests for SP 800-56A Rev3 On session Table 20: Conditional Self-Tests 10.3 Periodic Self-Test Information Page 76 of 80 Algorithm or Test Test Method Test Type Period Periodic Method ECDSA SigVer (FIPS186-4) (A2906) KAT SW/FW Integrity On Demand Manually or Scheduled HMAC-SHA2- 256 (A2906) KAT SW/FW Integrity On Demand Manually or Scheduled Table 21: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES GCM (A2906) Decrypt KAT CAST On Demand Manually or Scheduled AES GCM (A2906) Encrypt KAT CAST On Demand Manually or Scheduled AES-ECB (A2906) Decrypt KAT CAST On Demand Manually or Scheduled Counter DRBG (A2906) KAT CAST On Demand Manually or Scheduled ECDSA KeyGen (FIPS186-4) (A2906) PCT PCT On session On session ECDSA SigGen (FIPS186-4) (A2906) KAT CAST On Demand Manually or Scheduled ECDSA SigVer (FIPS186-4) (A2906) KAT CAST On Demand Manually or Scheduled Firmware Load Test FW Load Test SW/FW Load On session On session HMAC-SHA-1 (A2906) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 224 (A2906) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 256 (A2906) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 384 (A2906) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 512 (A2906) KAT CAST On Demand Manually or Scheduled RSA KeyGen (FIPS186-4) (A2906) PCT PCT On session On session RSA SigGen (FIPS186-4) (A2906) KAT CAST On Demand Manually or Scheduled RSA SigVer (FIPS186-4) (A2906) KAT CAST On Demand Manually or Scheduled Page 77 of 80 Algorithm or Test Test Method Test Type Period Periodic Method Safe Primes Key Generation (A2906) PCT PCT On session On session SHA-1 (A2906) KAT CAST On Demand Manually or Scheduled SHA2-256 (A2906) KAT CAST On Demand Manually or Scheduled SHA2-384 (A2906) KAT CAST On Demand Manually or Scheduled SHA2-512 (A2906) KAT CAST On Demand Manually or Scheduled SP 800-90B APT Health Tests on Entropy Source Fault detection CAST On Demand Manually or Scheduled SP 800-90B RCT Health Tests on Entropy Source Fault detection CAST On Demand Manually or Scheduled SP 800-135rev1 IKEv2 KDF with SHA-256 KAT CAST On Demand Manually or Scheduled SP 800-135rev1 SSH KDF with SHA-256 KAT CAST On Demand Manually or Scheduled SP 800-135rev1 TLS 1.2 with SHA-256 KDF KAT CAST On Demand Manually or Scheduled SP 800-56A Rev 3 Assurance Tests Critical Functions Critical Function On session On session Table 22: Conditional Periodic Information 10.4 Error States Name Description Conditions Recovery Method Indicator Conditional Firmware Load Test Failure Signature verification fails on firmware load Signature verification failure N/A System prints Invalid image message. Conditional Pairwise Consistency or Critical Functions Test Failure Module fails a PCT or critical functions test PCT / Critical functions test Reset session System log prints an error message. Page 78 of 80 Name Description Conditions Recovery Method Indicator Self-Test / Integrity Test Failure Module fails a self-test or integrity test Self-test or Integrity Test failure Reboot Module or Factory Reset FIPS-CC mode failure. failed. Table 23: Error States 10.5 Operator Initiation of Self-Tests Perform a power cycle or via the ‘Self-Tests’ service by entering CLI command “request restart system” 11 Life-Cycle Assurance 11.1 Installation, Initialization, and Startup Procedures The following procedure will put the modules into the Approved mode of operation: • Install physical kit opacity shields and tamper evidence seals according to the Physical Security Policy section. Physical kits must be correctly installed to operate in the Approved mode of operation. The tamper evidence seals and opacity shields shall be installed for the module to operate in the Approved mode of operation. • During initial boot up, break the boot sequence via the console port connection (by pressing the main button when instructed to do so) to access the main menu. • Select “Continue.” • Select the “Set FIPS-CC Mode” option to enter the Approved mode. • Select “Enable FIPS-CC Mode”. • When prompted, select “Reboot” and the module will re-initialize and continue into Approved mode. • The module will reboot. • In Approved mode, the console port is available as a status output port. • Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module • Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten The module will automatically indicate the Approved mode of operation in the following manner: • Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session. • Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port. • The module will display “FIPS-CC” at all times in the status bar at the bottom of the web interface. Page 79 of 80 Should one or more power-up self-tests fail, the Approved mode of operation will not be achieved. Feedback will consist of: • The module will output “FIPS-CC failure” • The module will reboot and enter a state in which the reason for the reboot can be determined. To determine which self-test caused the system to reboot into the error state, connect the console cable and follow the on-screen instructions to view the self-test output. Note: Disabling Approved mode causes a complete factory reset, which is described in the Zeroization section below. Failure to follow the installation/instructions steps in Section 11.1 would result in the module operating in a non-compliant state 11.2 Administrator Guidance The Administrator Guidance can be obtained from Palo Alto Network’s public site: https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/advanced-wildfire/wildfire- appliance.pdf 11.3 Non-Administrator Guidance N/A 11.4 Design and Rules In Approved mode, the following rules shall apply: 1. The operator should not enable or use TLSv1.3 • Checked via CLI using “show profiles” command 2. If using RADIUS, it must be configured using TLS • Checked via CLI using “show shared” command Failure to follow these Security Rules will cause the module to operate in a non-compliant state. 11.5 End of Life The following procedure will zeroize the module: ● Access the module’s CLI via SSH, and command the module to enter maintenance mode; the module will reboot Note: Establish a serial connection to the console port ● After reboot, select “Continue.” ● Select “Factory Reset” ● The module will perform a zeroization, and provide the following message once complete: o “Factory Reset Status: Success” Page 80 of 80 Note: Following the completion of this procedure, the module will be placed back into an uninitialized state. 12 Mitigation of Other Attacks N/A