Page 1 of 91 Palo Alto Networks, Inc Panorama Virtual Appliance 10.2 FIPS 140-3 Non-Proprietary Security Policy Page 2 of 91 Table of Contents 1 General......................................................................................................................................... 5 1.1 Overview............................................................................................................................... 5 1.2 Security Levels...................................................................................................................... 5 2 Cryptographic Module Specification........................................................................................... 5 2.1 Description ............................................................................................................................ 5 2.2 Tested and Vendor Affirmed Module Version and Identification ........................................ 7 2.4 Modes of Operation............................................................................................................... 8 2.5 Algorithms............................................................................................................................. 8 2.6 Security Function Implementations .................................................................................... 11 2.7 Algorithm Specific Information.......................................................................................... 20 2.7.1 IG C.H Conformance:................................................................................................... 20 2.7.2 IG C.F Conformance: ................................................................................................... 21 2.7.3 IG C.K Conformance:................................................................................................... 21 2.8 RBG and Entropy................................................................................................................ 21 2.9 Key Generation ................................................................................................................... 21 2.10 Key Establishment............................................................................................................. 22 2.11 Industry Protocols ............................................................................................................. 22 3 Cryptographic Module Interfaces .............................................................................................. 22 3.1 Ports and Interfaces ............................................................................................................. 22 4 Roles, Services, and Authentication .......................................................................................... 23 4.1 Authentication Methods...................................................................................................... 23 4.2 Roles.................................................................................................................................... 24 4.3 Approved Services .............................................................................................................. 24 4.4 Non-Approved Services...................................................................................................... 63 4.5 External Software/Firmware Loaded .................................................................................. 63 5 Software/Firmware Security...................................................................................................... 63 5.1 Integrity Techniques............................................................................................................ 63 5.2 Initiate on Demand.............................................................................................................. 63 6 Operational Environment........................................................................................................... 64 6.1 Operational Environment Type and Requirements............................................................. 64 7 Physical Security........................................................................................................................ 64 8 Non-Invasive Security ............................................................................................................... 64 9 Sensitive Security Parameters Management.............................................................................. 64 Page 3 of 91 9.1 Storage Areas ...................................................................................................................... 64 9.2 SSP Input-Output Methods ................................................................................................. 64 9.3 SSP Zeroization Methods.................................................................................................... 65 9.4 SSPs..................................................................................................................................... 66 10 Self-Tests ................................................................................................................................. 82 10.1 Pre-Operational Self-Tests ................................................................................................ 82 10.2 Conditional Self-Tests....................................................................................................... 83 10.3 Periodic Self-Test Information.......................................................................................... 86 10.4 Error States........................................................................................................................ 88 10.5 Operator Initiation of Self-Tests ....................................................................................... 89 11 Life-Cycle Assurance............................................................................................................... 89 11.1 Installation, Initialization, and Startup Procedures ........................................................... 89 11.2 Administrator Guidance.................................................................................................... 90 11.3 Non-Administrator Guidance............................................................................................ 90 11.4 Design and Rules............................................................................................................... 90 11.6 End of Life ........................................................................................................................ 90 12 Mitigation of Other Attacks..................................................................................................... 91 Page 4 of 91 List of Tables Table 1: Security Levels ................................................................................................................. 5 Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets).... 7 Table 3: Tested Operational Environments - Software, Firmware, Hybrid.................................... 8 Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid .................. 8 Table 5: Modes List and Description.............................................................................................. 8 Table 6: Approved Algorithms..................................................................................................... 10 Table 7: Vendor-Affirmed Algorithms......................................................................................... 11 Table 8: Security Function Implementations................................................................................ 20 Table 9: Entropy Certificates........................................................................................................ 21 Table 10: Entropy Sources............................................................................................................ 21 Table 11: Ports and Interfaces....................................................................................................... 23 Table 12: Authentication Methods................................................................................................ 24 Table 13: Roles ............................................................................................................................. 24 Table 14: Approved Services........................................................................................................ 63 Table 15: Storage Areas................................................................................................................ 64 Table 16: SSP Input-Output Methods........................................................................................... 65 Table 17: SSP Zeroization Methods ............................................................................................. 66 Table 18: SSP Table 1................................................................................................................... 74 Table 19: SSP Table 2................................................................................................................... 82 Table 20: Pre-Operational Self-Tests............................................................................................ 83 Table 21: Conditional Self-Tests .................................................................................................. 86 Table 22: Pre-Operational Periodic Information .......................................................................... 86 Table 23: Conditional Periodic Information................................................................................. 88 Table 24: Error States ................................................................................................................... 88 List of Figures Figure 1: Block Diagram ................................................................................................................ 6 Page 5 of 91 1 General 1.1 Overview The Panorama Virtual Appliance 10.2 from Palo Alto Networks Inc., hereafter referred to as “Panorama Virtual Appliance“ or the “cryptographic module” are multi-chip standalone cryptographic modules designed to fulfill FIPS 140-3 level 1 requirements. The Panorama Virtual Appliance provides centralized monitoring and management of multiple Palo Alto Networks next-generation (NG) firewalls and Wildfire appliances. For purposes of this validation, the exact software versions of the module tested was 10.2.3-h1. The cryptographic module meets the overall requirements applicable to Level 1 security of FIPS 140-3. This document may freely be reproduced and distributed in its entirety. 1.2 Security Levels Section Title Security Level 1 General 1 2 Cryptographic module specification 1 3 Cryptographic module interfaces 1 4 Roles, services, and authentication 3 5 Software/Firmware security 1 6 Operational environment 1 7 Physical security N/A 8 Non-invasive security N/A 9 Sensitive security parameter management 1 10 Self-tests 1 11 Life-cycle assurance 3 12 Mitigation of other attacks N/A Overall Level 1 Table 1: Security Levels 2 Cryptographic Module Specification 2.1 Description Purpose and Use: Panorama Virtual Appliance provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall. Module Type: Software Page 6 of 91 Module Embodiment: Multi-Chip Standalone Module Characteristics: Cryptographic Boundary: The Panorama Virtual Appliance is a software cryptographic module and requires an underlying general-purpose computer (GPC) environment. The module consists of a GPC (multi-chip standalone embodiment) with the cryptographic boundary defined below. The cryptographic boundary (CB) includes all of the software components of the module, which are included in the file name in Section 11 (Panorama_pc-10.2.3-h1) and also the configuration file that resides on the virtual machine’s virtual disk. The physical perimeter (PP) is defined by the enclosure around the host GPC on which it runs. Figure 1 depicts the boundary and illustrates the hardware components of a GPC. Figure 1: Block Diagram Page 7 of 91 Tested Operational Environment’s Physical Perimeter (TOEPP): See above. 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Hardware: N/A for this module. Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): Package or File Name Software/ Firmware Version Features Integrity Test Panorama_pc-10.2.3- h1 10.2.3-h1 N/A Yes Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: The module is a modifiable operational environment as per FIPS 140-3 Level 1 specifications. The hypervisor environment provides an isolated operating environment and is the single operator of the virtual machine. The tested operating environments isolate virtual systems into separate isolated process spaces. Each process space is logically separated from all other processes by the operating environments software and hardware. The module functions entirely within the process space of the isolated system as managed by the single operational environment. This implicitly meets the FIPS 140-3 requirement that only one (1) entity at a time can use the cryptographic module. Operating System Hardware Platform Processors PAA/PAI Hypervisor or Host OS Version(s) N/A Dell PowerEdge R740 Intel Xeon Gold 6248 (Cascade Lake) No Hyper-V 2019 on Microsoft Hyper-V Server 2019 10.2.3-h1 N/A Dell PowerEdge R740 Intel Xeon Gold 6248 (Cascade Lake) No KVM 4 on Ubuntu 20.04 10.2.3-h1 N/A Dell PowerEdge R740 Intel Xeon Gold 6248 (Cascade Lake) No VMware ESXi v7.0 10.2.3-h1 Page 8 of 91 Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: Operating System Hardware Platform Amazon Web Services (AWS) x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system) Google Cloud Platform (GCP) x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system) Microsoft Azure x86 Architecture (Note: Specific processor/hardware is dependent on Instance/Machine Type selected for operation system) Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. 2.4 Modes of Operation Modes List and Description: The module only operates in an approved mode of operation and is in the approved mode when installed, initialized and configured per section 11.1 of the Security Policy. Mode Name Description Type Status Indicator Approved Mode The module has one approved mode of operation and is always in approved mode after initialization Approved Global indicator ("FIPS-CC") Table 5: Modes List and Description Mode Change Instructions and Status: See Life-Cycle Assurance section. 2.5 Algorithms Approved Algorithms: Algorithm CAVP Cert Properties Reference AES-CBC A2907 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A Page 9 of 91 Algorithm CAVP Cert Properties Reference AES-CFB128 A2907 Direction - Decrypt, Encrypt Key Length - 128 SP 800-38A AES-CTR A2907 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - No Counter Tests Performed - No SP 800-38A AES-GCM A2907 Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256 SP 800-38D Counter DRBG A2907 Prediction Resistance - No, Yes Mode - AES-256 Derivation Function Enabled - Yes SP 800-90A Rev. 1 ECDSA KeyGen (FIPS186-4) A2907 Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates FIPS 186-4 ECDSA KeyVer (FIPS186-4) A2907 Curve - P-256, P-384, P-521 FIPS 186-4 ECDSA SigGen (FIPS186-4) A2907 Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 ECDSA SigVer (FIPS186-4) A2907 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Curve - P-256, P-384, P-521 FIPS 186-4 HMAC-SHA-1 A2907 MAC - MAC: 160 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 224 A2907 MAC - MAC: 224 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 256 A2907 MAC - MAC: 256 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 384 A2907 MAC - MAC: 384 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 HMAC-SHA2- 512 A2907 MAC - MAC: 512 Key Length - Key Length: 256-2048 Increment 8 FIPS 198-1 KAS-ECC-SSC Sp800-56Ar3 A2907 Domain Parameter Generation Methods - P- 256, P-384, P-521 SP 800-56A Rev. 3 Page 10 of 91 Algorithm CAVP Cert Properties Reference Scheme - ephemeralUnified - KAS Role - initiator, responder KAS-FFC-SSC Sp800-56Ar3 A2907 Domain Parameter Generation Methods - MODP-2048 Scheme - dhEphem - KAS Role - initiator, responder SP 800-56A Rev. 3 KDF SNMP (CVL) A2907 Password Length - Password Length: 64, 2048 Engine ID - 80001F88043030303030343935323630 SP 800-135 Rev. 1 KDF SSH (CVL) A2907 Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2- 512 SP 800-135 Rev. 1 KDF TLS (CVL) A2907 TLS Version - v1.2 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 RSA KeyGen (FIPS186-4) A2907 Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Private Key Format - Standard FIPS 186-4 RSA SigGen (FIPS186-4) A2907 Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 FIPS 186-4 RSA SigVer (FIPS186-4) A2907 Signature Type - ANSI X9.31, PKCSPSS Modulo - 2048, 3072, 4096 FIPS 186-4 Safe Primes Key Generation A2907 Safe Prime Groups - MODP-2048 SP 800-56A Rev. 3 Safe Primes Key Verification A2907 Safe Prime Groups - MODP-2048 SP 800-56A Rev. 3 SHA-1 A2907 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 SHA2-224 A2907 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-256 A2907 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-384 A2907 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 SHA2-512 A2907 Message Length - Message Length: 0-65536 Increment 8 FIPS 180-4 Table 6: Approved Algorithms Page 11 of 91 Note: Only the algorithms specified in the table above are supported by the module in approved mode of operation. Vendor-Affirmed Algorithms: Name Properties Implementation Reference CKG (SP 800- 133rev2) Key Type:Asymmetric N/A Cryptographic Key Generation; SP 800-133rev2 and IG D.H (asymmetric seeds) from Section 4 Example 1 Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module. 2.6 Security Function Implementations Name Type Description Properties Algorithms KAS-ECC (SSH) KAS-Full Full KAS- ECC Key Agreement used for SSHv2 service IG:D.F Scenario 2 path 2, split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL Caveat: Key establishment methodology providing between 128 and 256 bits of security strength KAS-ECC- SSC Sp800- 56Ar3: (A2907) KDF SSH: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) Page 12 of 91 Name Type Description Properties Algorithms KAS-ECC (TLSv1.2) KAS-Full Full KAS- ECC Key Agreement used for TLSv1.2 service IG:D.F Scenario 2 path 2, split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL Caveat:Key establishment methodology providing between 128 and 256 bits of security strength KAS-ECC- SSC Sp800- 56Ar3: (A2907) KDF TLS: (A2907) HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) KAS-ECC-KeyGen (SSH) CKG KAS-KeyGen KAS ECC keygen used in SSHv2 service Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric KAS-ECC-KeyGen (TLSv1.2) CKG KAS-KeyGen KAS ECC keygen used in TLSv1.2 service Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric KAS-FFC (SSH) KAS-Full Full KAS-FFC Key Agreement used for SSHv2 service IG:D.F Scenario 2 path 2, split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVL Caveat:Key establishment methodology providing between 128 and KAS-FFC- SSC Sp800- 56Ar3: (A2907) KDF SSH: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) Page 13 of 91 Name Type Description Properties Algorithms 256 bits of security strength KAS-FFC (TLSv1.2) KAS-Full Full KAS-FFC Key Agreement used for TLSv1.2 service IG:D.F Scenario 2 path 2, split Key Confirmation:No Key Derivation:2.4.B SP 800-135rev1 CVL Caveat:Key establishment methodology providing between 128 and 256 bits of security strength KAS-FFC- SSC Sp800- 56Ar3: (A2907) KDF TLS: (A2907) Safe Primes Key Generation: (A2907) Safe Primes Key Verification: (A2907) HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) KAS-FFC-KeyGen (SSH) CKG KAS-KeyGen KAS FFC keygen used in SSHv2 service Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric KAS-FFC-KeyGen (TLSv1.2) CKG KAS-KeyGen KAS FFC keygen used in TLSv1.2 service Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric KTS (SSHv2 with AES and HMAC) KTS-Wrap KTS via SSHv2 service Standard:SP 800-38F IG AES-CBC: (A2907) HMAC- Page 14 of 91 Name Type Description Properties Algorithms by using AES and HMAC D.G:Approved Key Wrapping Caveat:Key establishment methodology provides between 128 and 256 bits of security strength SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) KTS (SSHv2 with AES-GCM) KTS-Wrap KTS via SSHv2 service by using AES- GCM Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology provides between 128 and 256 bits of security strength AES-GCM: (A2907) AES-CBC: (A2907) KTS (TLSv1.2 with AES and HMAC) KTS-Wrap KTS via TLSv1.2 service by using AES and HMAC Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology provides between 128 and 256 bits of security strength AES-CBC: (A2907) HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) KTS (TLSv1.2 with AES-GCM) KTS-Wrap KTS via TLSv1.2 service by using AES- GCM Standard:SP 800-38F IG D.G:Approved Key Wrapping Caveat:Key establishment methodology provides between 128 and 256 bits of security strength AES-GCM: (A2907) AES-CBC: (A2907) Page 15 of 91 Name Type Description Properties Algorithms Session Authentication (SNMPv3) MAC SNMPv3 session authentication HMAC-SHA- 1: (A2907) HMAC- SHA2-224: (A2907) SHA-1: (A2907) SHA2-224: (A2907) Session Authentication (SSHv2) MAC SSHv2 session authentication HMAC-SHA- 1: (A2907) HMAC- SHA2-256: (A2907) HMAC- SHA2-512: (A2907) SHA-1: (A2907) SHA2-256: (A2907) SHA2-512: (A2907) Session Authentication (TLSv1.2) MAC TLSv1.2 session authentication HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) Session Encryption/Decryption (SNMPv3) BC-Auth BC-UnAuth SNMPv3 session protection AES-CFB128: (A2907) Session Encryption/Decryption (SSH) BC-Auth BC-UnAuth SSHv2 session protection AES-CBC: (A2907) AES-CTR: (A2907) AES-GCM: (A2907) Session Encryption/Decryption (TLSv1.2) BC-Auth BC-UnAuth TLSv1.2 session protection AES-CBC: (A2907) Page 16 of 91 Name Type Description Properties Algorithms AES-GCM: (A2907) SNMPv3 Keying Materials Development KAS-135KDF SNMPv3 session keying materials, used to derive SNMPv3 session keys KDF SNMP: (A2907) SHA-1: (A2907) Software Load Test DigSig-SigVer Signature verification for software load test RSA SigVer (FIPS186-4): (A2907) SHA2-256: (A2907) SSH ECDSA KeyGen AsymKeyPair- KeyGen CKG ECDSA KeyGen for SSHv2 ECDSA KeyGen (FIPS186-4): (A2907) Counter DRBG: (A2907) SSH ECDSA SigGen DigSig- SigGen ECDSA SigGen for SSHv2 ECDSA SigGen (FIPS186-4): (A2907) SHA2-224: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) SSH ECDSA SigVer DigSig-SigVer ECDSA SigVer for SSHv2 ECDSA SigVer (FIPS186-4): (A2907) ECDSA KeyVer (FIPS186-4): (A2907) SHA-1: (A2907) SHA2-224: (A2907) SHA2-256: Page 17 of 91 Name Type Description Properties Algorithms (A2907) SHA2-384: (A2907) SHA2-512: (A2907) SSH RSA KeyGen AsymKeyPair- KeyGen CKG RSA KeyGen for SSHv2 RSA KeyGen (FIPS186-4): (A2907) Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric SSH RSA SigGen DigSig- SigGen RSA SigGen for SSHv2 RSA SigGen (FIPS186-4): (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) SSH RSA SigVer DigSig-SigVer RSA SigVer for SSHv2 RSA SigVer (FIPS186-4): (A2907) SHA-1: (A2907) SHA2-224: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) SSHv2 Keying Materials Development KAS-135KDF SSHv2 session keying materials, used to derive SSHv2 session keys KDF SSH: (A2907) SHA-1: (A2907) SHA2-256: (A2907) Page 18 of 91 Name Type Description Properties Algorithms SHA2-512: (A2907) TLS ECDSA KeyGen AsymKeyPair- KeyGen CKG ECDSA KeyGen for TLSv1.2 ECDSA KeyGen (FIPS186-4): (A2907) Counter DRBG: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric TLS ECDSA SigGen DigSig- SigGen ECDSA SigGen for TLSv1.2 ECDSA SigGen (FIPS186-4): (A2907) Counter DRBG: (A2907) SHA2-224: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) TLS ECDSA SigVer DigSig-SigVer ECDSA SigVer for TLSv1.2 ECDSA SigVer (FIPS186-4): (A2907) ECDSA KeyVer (FIPS186-4): (A2907) SHA-1: (A2907) SHA2-224: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) Page 19 of 91 Name Type Description Properties Algorithms SHA2-512: (A2907) TLS RSA KeyGen AsymKeyPair- KeyGen CKG RSA KeyGen for TLSv1.2 RSA KeyGen (FIPS186-4): (A2907) Counter DRBG: (A2907) KDF TLS: (A2907) CKG (SP 800- 133rev2): () Key Type: Symmetric and Asymmetric HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) TLS RSA SigGen DigSig- SigGen RSA SigGen for TLSv1.2 RSA SigGen (FIPS186-4): (A2907) SHA2-256: (A2907) SHA2-384: (A2907) SHA2-512: (A2907) TLS RSA SigVer DigSig-SigVer RSA SigVer for TLSv1.2 RSA SigVer (FIPS186-4): (A2907) SHA-1: (A2907) SHA2-224: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) Page 20 of 91 Name Type Description Properties Algorithms SHA2-512: (A2907) TLSv1.2 Keying Materials Development KAS-135KDF TLSv1.2 session keying materials, used to derive TLSv1.2 session keys KDF TLS: (A2907) HMAC- SHA2-256: (A2907) HMAC- SHA2-384: (A2907) SHA2-256: (A2907) SHA2-384: (A2907) Table 8: Security Function Implementations 2.7 Algorithm Specific Information 2.7.1 IG C.H Conformance: GCM is used in the context of TLS, SSH: • For TLS, The GCM implementation meets Scenario 1 of IG C.H: it is used in a manner compliant with SP 800-52rev2 and in accordance with Section 4 of RFC 5288 for TLS key establishment, and ensures when the nonce_explicit part of the IV exhausts all possible values for a given session key, that a new TLS handshake is initiated per sections 7.4.1.1 and 7.4.1.2 of RFC 5246. During operational testing, the module was tested against an independent version of TLS and found to behave correctly o From this RFC, the GCM cipher suites in use are TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, and TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. • For SSH, the module meets Scenario 1 of IG C.H. The module conforms to RFCs 4252, 4253, and 5647. The fixed field is 32 bits in length and is derived using the SSH KDF; this ensures the fixed field is unique for any given GCM session. The invocation field is 64 bits in length and is incremented for each invocation of GCM; this prevents the IV from repeating until the entire invocation field space of 264 is exhausted. (It would take hundreds of years for this to occur.) Page 21 of 91 In all of the above cases, the nonce explicit is always generated deterministically. AES GCM keys are zeroized when the module is power cycled. For each new TLS or SSH session, a new AES GCM key is established. 2.7.2 IG C.F Conformance: The module utilizes Approved modulus sizes 2048, 3072, and 4096 bits for RSA signatures. This functionality has been CAVP tested as noted above. The minimum number of Miller Rabin tests for each modulus size is implemented according to Table C.2 of FIPS 186-4. For modulus size 4096, the module implements the largest number of Miller-Rabin tests shown in Table C.2. RSA SigVer is CAVP tested for all three supported modulus sizes as noted above. The module does not perform FIPS 186-2 SigVer. All supported modulus sizes are CAVP testable and tested as noted above. The module does not implement RSA key transport in the approved mode. 2.7.3 IG C.K Conformance: The CAVP testing for Cert. #A2907 was performed prior to the transition date for this IG. Additionally, The FIPS 186-4 CAVP implemented in this module tests are mathematically identical to FIPS 186-5 tests. 2.8 RBG and Entropy Cert Number Vendor Name E69 Palo Alto Networks Table 9: Entropy Certificates Name Type Operational Environment Sample Size Entropy per Sample Conditioning Component Palo Alto Networks DRNG Entropy Source - Skylake 28 Core Die with FCLGA3647 Package Physical Intel Corporation Intel(R) Xeon(R) Skylake-28 FCLGA3647 Intel(R) Xeon(R) Platinum 8276CL Processor 128 128 A1791 (AES- CBC-MAC) Table 10: Entropy Sources The Intel DRNG utilizes a vetted conditioner (AES-CBC-MAC) that outputs full entropy (128- bits per 128-bits of output). Upon boot, the AES-256 Counter DRBG (security strength of 256- bits) requests 384-bits from the Intel DRNG entropy source. Therefore, it is fully seeded with 384 bits of entropy. 2.9 Key Generation Page 22 of 91 The module implements CKG where symmetric keys and seeds used for asymmetric key pair generation are produced using the unmodified/direct output of the DRBG. 2.10 Key Establishment The module provides the following key/SSP establishment services in the approved mode of operation: • KAS-ECC Shared Secret Computation The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (1) with KAS-ECC shared secret computation. The shared secret computation provides between 128 and 256 bits of encryption strength. • KAS-FFC Shared Secret Computation The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (1) with KAS-FFC shared secret computation. The shared secret computation provides between 112 and 150 bits of encryption strength. 2.11 Industry Protocols • TLS 1.2 • SSHv2 • SNMPv3 No parts of the SSH, TLS and SNMP protocols, other than the KDFs, have been tested by the CAVP/CMVP. 3 Cryptographic Module Interfaces The modules are multi-chip standalone modules with ports and interfaces as shown below. The modules do not implement a control output interface. 3.1 Ports and Interfaces Physical Port Logical Interface(s) Data That Passes N/A Status Output Self-test status output N/A Data Input Data Output Control Input Control Output Status Output HTTPS, TLS, SNMP and SSH traffic data. N/A Power Power supplies Page 23 of 91 Table 11: Ports and Interfaces 4 Roles, Services, and Authentication 4.1 Authentication Methods Method Name Description Security Mechanism Strength Each Attempt Strength per Minute RSA- Based Certificate The modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits RSA SigVer (FIPS186-4) (A2907) With a minimum modulus size of 2048, the probability that a random attempt will succeed is 1/(2^112). The probability of successfully authenticating to the module within a one- minute period is 288,000,000/(2^112). The module supports at most 4,800,000 new sessions per second. ECDSA- Based Certificate The modules support ECDSA public- key based authentication mechanism using a minimum ECDSA curve of P-256 ECDSA SigVer (FIPS186-4) (A2907) With a minimum curve of P-256, the probability that a random attempt will succeed is 1/(2^128). The probability of successfully authenticating to the module within a one- minute period is 288,000,000/(2^112). The module supports at most 4,800,000 new sessions per second. Password Password based authentication Password Based The minimum length is eight (8) characters (95 possible characters). The probability that a random attempt will succeed or a false acceptance will occur is 1/(95^8). The probability of successfully authenticating to the module within one minute is 10/(95^8). The firewall's configuration supports at most ten failed attempts to authenticate in a one- minute period. Pre- Shared Secret PSK authentication Password Based The pre-shared key authentication method has a minimum security strength of 95^6. The probability of successfully The probability of successfully authenticating to the module within a one minute period is 288,000,000/(95^6). Page 24 of 91 Method Name Description Security Mechanism Strength Each Attempt Strength per Minute authenticating to the module is 1/(95^6). The number of authentication attempts is limited by the number of new connections per second supported (4,800,000) on the fastest platform of the Palo Alto Networks firewalls. Table 12: Authentication Methods 4.2 Roles Name Type Operator Type Authentication Methods Crypto Officer Identity CO RSA-Based Certificate ECDSA-Based Certificate Password Pre-Shared Secret User Role User RSA-Based Certificate ECDSA-Based Certificate Password Pre-Shared Secret Table 13: Roles 4.3 Approved Services Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Access CLI Connect to module's CLI via SSH System Logs Input comman d for CLI Configurati on items via CLI KAS-ECC (SSH) KAS-ECC- KeyGen (SSH) KAS-FFC (SSH) KAS-FFC- KeyGen (SSH) Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: Page 25 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) Session Authentication (SSHv2) Session Encryption/Decr yption (SSH) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z Page 26 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z User - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: Page 27 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access G,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Page 28 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Secret: G,E,Z Access Web Portal Connect to module's web portal to invoke services. (Panorama or Manageme nt-Only Mode System Logs Accessin g web browser Module options via web browser KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (TLSv1.2) Session Encryption/Decr yption (TLSv1.2) TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLSv1.2 Keying Materials Development Crypto Officer - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - Entropy Input String: G,E - RSA Private Keys: G,W,E - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Page 29 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z User - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - Entropy Input String: G,E - RSA Private Keys: G,W,E - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS Page 30 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Configure High Availabilit y Configure High Availabilit y communic ation settings (Panorama or Manageme nt-Only Mode) System and Configura tion Logs Configur ing high availabil ity High availability configured KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: Page 31 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Page 32 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access TLS RSA SigGen TLS RSA SigVer Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Page 33 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Configure Managed Log Collectors Setup and manage other Log Collector manageme nt, communic ation and storage settings View current deploymen t informatio n on the managed Log Collectors. It also allows you to manage software versions and schedule updates on managed log collectors. (Panorama or Manageme nt-Only Mode) System and Configura tion Logs Configur ing log collector s Operation of log collectors KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic Page 34 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Page 35 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Manage Panorama Administr ative Access Manage RSA/ECD SA certificates and private keys, certificate profiles, revocation status, and usage; show status. (Panorama System and Configura tion Logs Configur ing certificat es Certificate output and status KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG Page 36 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access , Manageme nt-Only, or Log Collector Mode) KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: W,E - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD Page 37 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLSv1.2 Keying Materials Development HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: Page 38 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Monitor System Status and Logs Review system status via the panorama system CLI, dashboard and logs; show status. (Panorama or Manageme nt-Only Mode) System Logs Comman ds for system status / logs Current status of module and functions KAS-ECC (SSH) KAS-ECC- KeyGen (SSH) KAS-FFC (SSH) KAS-FFC- KeyGen (SSH) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) Session Authentication (SSHv2) Session Encryption/Decr yption (SSH) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E Page 39 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z Panorama Certificate Managem ent Manage RSA/ECD SA certificates and private keys, certificate profiles, System and Configura tion Logs Configur ing certificat es Certificate output and status KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: Page 40 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access revocation status, and usage; show status. (Panorama , Manageme nt-Only, or Log Collector Mode) (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: W,E - SNMPv3 Authentic ation Secret: G,E,Z - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Page 41 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer Session Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Page 42 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Panorama Log Collector Setup Presents configurati on options for manageme nt interfaces and communic ation for peer services Import, Export, Save, Load, revert and validate Panorama configurati ons and state. (Log Collector Mode only) System and Configura tion Logs Configur e options for log collector s Log collectors operation KAS-ECC (SSH) KAS-ECC- KeyGen (SSH) KAS-FFC (SSH) KAS-FFC- KeyGen (SSH) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) Session Authentication (SSHv2) Session Encryption/Decr yption (SSH) SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - RSA Private Page 43 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access SigGen SSH RSA SigVer SSHv2 Keying Materials Development Keys: G,W,E - RSA Public Keys: G,R,W,E - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z Page 44 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Panorama Log Setting Configure log forwarding (Panorama or Manageme nt-Only Mode) Configura tion Logs Configur ing log settings Log setting operations KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: W,E - SNMPv3 Authentic Page 45 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer ation Secret: W,E - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS Page 46 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access DHE/ECD HE Private Compone nts: G,W,E - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Panorama Manager Setup Presents configurati on options for manageme nt interfaces and communic ation for peer services (e.g., SNMP, RADIUS). System and Configura tion Logs Configur ing items on Panoram a Panorama settings configured KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E Page 47 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Import, Export, Save, Load, revert and validate Panorama configurati ons and state role (Panorama or Manageme nt-Only Mode) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Page 48 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: Page 49 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Panorama Server Profiles Configure communic ation parameters and informatio n for peer servers (Panorama or Manageme nt-Only Mode) System Logs Configur ing server profile settings Communic ation parameters setup KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Page 50 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Page 51 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,W,E - TLS Pre- Master Page 52 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Secret: G,W,E Panorama Software Update Download and install software updates System and Configura tion Logs Uploadi ng new software Installation of new software Software Load Test None Crypto Officer - Public key for software load test: E Self-Tests Run power up self- tests on demand by power cycling the module. System Logs Initiating self-test Completion of self-tests None Crypto Officer - Public key for software load test: E Setup Managed Devices and Deployme nt Set-up and define managed devices, device groups for firewalls Configure device deploymen t application s and licenses View current deploymen t informatio n on the managed firewalls. It also allows you to manage software versions and Configura tion Logs Setting up devices Controlling managed devices KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,E,Z - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Page 53 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access schedule updates on the managed firewalls and managed log collectors. (Panorama or Manageme nt-Only Mode) with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z Page 54 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z Page 55 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access - TLS Pre- Master Secret: G,E,Z Show Status View status of the module FIPS-CC Mode Indicator Initiating show status comman d Status of the module provided None Crypto Officer Show Version Query the module to display the version Version displayed via System Logs / CLI / UI Input comman d for show version version information None Crypto Officer System Audit Allows review of limited configurati on and system status via SNMPv3, logs, dashboard, show status, and configurati on screens. CO Only: Provides configurati on commit capability. (Panorama , Manageme nt-Only, or PAN-DB Mode) System Logs Comman ds for showing device setup System details KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,E,Z - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,E,Z - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: Page 56 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen W,E - RSA Private Keys: G,E,Z - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Page 57 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Page 58 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Master Secret: G,E,Z System Provisioni ng Perform panorama licensing, diagnostics , debug functions, manage Panorama support informatio n and switch between Panorama Manageme nt-only, and Logger modes. (Panorama or Manageme nt-Only Mode) System and Configura tion logs Input comman ds for system provisio ning System setup functions KAS-ECC (SSH) KAS-ECC (TLSv1.2) KAS-ECC- KeyGen (SSH) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC (SSH) KAS-FFC (TLSv1.2) KAS-FFC- KeyGen (SSH) KAS-FFC- KeyGen (TLSv1.2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) Session Authentication (SNMPv3) Session Authentication (SSHv2) Session Authentication (TLSv1.2) Session Encryption/Decr Crypto Officer - CA Certificate s: G,R,W,E - CO, User Password: G,W,E - DRBG Key: G,E - DRBG Seed: G,E - DRBG V: G,E - ECDSA Private Keys: G,W,E - ECDSA Public Key: G,R,W,E - Entropy Input String: G,E - Protocol Secrets: W,E - RSA Private Keys: G,W,E - RSA Public Keys: G,R,W,E - SNMPv3 Authentic ation Key: Page 59 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access yption (SNMPv3) Session Encryption/Decr yption (SSH) Session Encryption/Decr yption (TLSv1.2) SNMPv3 Keying Materials Development SSH ECDSA KeyGen SSH ECDSA SigGen SSH ECDSA SigVer SSH RSA KeyGen SSH RSA SigGen SSH RSA SigVer SSHv2 Keying Materials Development TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLSv1.2 Keying Materials Development G,E,Z - SNMPv3 Authentic ation Secret: W,E - SNMPv3 Privacy Secret: G,E,Z - SNMPv3 Session Key: G,E,Z - SSH Client Public Key: W,E - SSH DHE/ECD HE Private Compone nts: G,E,Z - SSH DHE/ECD HE Public Compone nts: G,R,W,E, Z - SSH Host Public Key: W,E - SSH Session Authentic ation Keys: G,E,Z - SSH Session Encryptio Page 60 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access n Keys: G,E,Z - SSH Shared Secret: G,E,Z - TLS DHE/ECD HE Private Compone nts: G,E,Z - TLS DHE/ECD HE Public Compone nts: G,R,W,E, Z - TLS Encryptio n Keys: G,E,Z - TLS HMAC Keys: G,E,Z - TLS Master Secret: G,E,Z - TLS Pre- Master Secret: G,E,Z Zeroize Zeroize all SSPs Zeroizatio n indicator Initiating zeroize comman d Zeroization performed on module None Crypto Officer - CA Certificate s: Z - CO, User Password: Z - DRBG Page 61 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Key: Z - DRBG Seed: Z - DRBG V: Z - ECDSA Private Keys: Z - ECDSA Public Key: Z - Entropy Input String: Z - Protocol Secrets: Z - Public key for software load test: Z - RSA Private Keys: Z - RSA Public Keys: Z - SNMPv3 Authentic ation Key: Z - SNMPv3 Authentic ation Secret: Z - SNMPv3 Privacy Secret: Z - SNMPv3 Session Key: Z - Software integrity verificatio Page 62 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access n key : Z - SSH Client Public Key: Z - SSH DHE/ECD HE Private Compone nts: Z - SSH DHE/ECD HE Public Compone nts: Z - SSH Session Authentic ation Keys: Z - SSH Session Encryptio n Keys: Z - SSH Shared Secret: Z - TLS DHE/ECD HE Private Compone nts: Z - TLS DHE/ECD HE Public Compone nts: Z - TLS Encryptio n Keys: Z - TLS HMAC Page 63 of 91 Name Descriptio n Indicator Inputs Outputs Security Functions SSP Access Keys: Z - TLS Master Secret: Z - TLS Pre- Master Secret: Z Table 14: Approved Services 4.4 Non-Approved Services N/A for this module. 4.5 External Software/Firmware Loaded The module supports the software load test by using RSA 2048 bits with SHA2-256 (RSA Cert. #A2907) for the new validated software to be uploaded into the module. A Software Load Test Key was preloaded to the module’s binary at the factory and used for software load test. In order to load new software, the Crypto Officer must authenticate into the module before loading any software. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. 5 Software/Firmware Security 5.1 Integrity Techniques The module’s executable code is in the form of the compiled software image loaded onto the module. The module performs the Software Integrity test by using HMAC-SHA2-256 (HMAC Cert..#A2907) during the Pre-Operational Self-Test. In addition, the module also conducts a software load test by using RSA 2048 with SHA2-256 (Cert. #A2907) for the new validated software to be uploaded into the module. Any software loaded into this module that is not shown on the module certificate is out of scope of this validation and requires a separate FIPS 140-3 validation. 5.2 Initiate on Demand Page 64 of 91 The pre-operational self-tests can be initiated by power cycling the module. When this is performed, the module automatically runs the cryptographic algorithm self-tests in addition to the pre-operational software integrity test. 6 Operational Environment 6.1 Operational Environment Type and Requirements Type of Operational Environment: Modifiable 7 Physical Security The module is a software only module; FIPS 140-3 physical security requirements are not applicable. 8 Non-Invasive Security Not applicable. 9 Sensitive Security Parameters Management 9.1 Storage Areas Storage Area Name Description Persistence Type HDD Non-Volatile Memory Static RAM Volatile Memory Dynamic Table 15: Storage Areas 9.2 SSP Input-Output Methods Name From To Format Type Distributio n Type Entry Type SFI or Algorith m Module Public Key Output HDD External (Outside of the Module's Plaintext Automated Electroni c Page 65 of 91 Name From To Format Type Distributio n Type Entry Type SFI or Algorith m Boundary ) Password/Secre t Input via SSHv2 encrypted by AES and HMAC External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (SSHv2 with AES and HMAC) Password/Secre t Input via SSHv2 encrypted by AES-GCM External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (SSHv2 with AES- GCM) Password/Secre t Input via TLSv1.2 encrypted by AES and HMAC External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (TLSv1.2 with AES and HMAC) Password/Secre t Input via TLSv1.2 encrypted by AES-GCM External (Outside of the Module's Boundary ) HDD Encrypte d Automated Electroni c KTS (TLSv1.2 with AES- GCM) Peer Public Key Input External HDD Plaintext Automated Electroni c Table 16: SSP Input-Output Methods 9.3 SSP Zeroization Methods Zeroization Method Description Rationale Operator Initiation Power Cycle / Session Termination Operator powers the module off or session terminates Powering off the module or terminating the session will erase all SSPs stored in the RAM of the module. Command via CLI or WebUI or by unplugging module Page 66 of 91 Zeroization Method Description Rationale Operator Initiation Zeroization Command CO issues zeroization service. The module's zeroization method is to overwrite the SSPs with a random pattern. The zeroization command will erase all SSPs stored in the RAM or in the Flash of the module. Once the module is rebooted and zeroization is initiated, the module cannot be accessed in any way to stop the zeroization process. Thus, the SSPs would not be compromised during the time of zeroization Entering into maintenance mode and selecting Factory Reset Table 17: SSP Zeroization Methods 9.4 SSPs Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By CA Certificate s ECDSA/RSA Public key - Used to trust a root CA intermediate CA and leaf /end entity certificates (RSA 2048, 3072, and 4096 bits) (ECDSA P- 256, P-384, and P-521) 2048 bits - 4096 bits - 112 bits - 152 bits Public Key - PSP TLS ECDSA KeyGen TLS RSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer TLS RSA SigGen CO, User Password Authenticatio n string with a minimum length of eight (8) characters. 8 charact ers minimu m - N/A Authentica tion Data - CSP - CSP DRBG Key AES 256 CTR DRBG state Key used in the generation of a random values 256 bits - 256 bits DRBG Key - CSP - CSP Counter DRBG (A2907) Counter DRBG (A2907) Page 67 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By DRBG Seed DRBG seed coming from the entropy source Seed length = 384 bits 384 bits - 256 bits DRBG Seed - CSP - CSP Entropy as per SP 800- 90B Counter DRBG (A2907) DRBG V AES 256 CTR DRBG state V used in the generation of a random values 128 bits - 128 bits DRBG Internal State V value - CSP - CSP Counter DRBG (A2907) Counter DRBG (A2907) ECDSA Private Keys ECDSA Private key for generation of signatures and authentication (P-256, P-384, or P-521) 128 - 256 bits - 128 - 256 bits Private Key - CSP ECDSA KeyGen (FIPS18 6-4) (A2907) TLS ECDSA SigGen ECDSA Public Key ECDSA public keys managed as certificates for the verification of signatures, establishment of TLS, operator authentication and peer authentication . (ECDSA P- 256, P-384, or P-521) 128 - 256 bits - 128 - 256 bits Public Key - PSP ECDSA KeyGen (FIPS18 6-4) (A2907) TLS ECDSA SigVer Entropy Input String Entropy input string coming from the entropy source Input length = 384 bits 384 bits - 256 bits DRBG - CSP - CSP Entropy as per SP 800- 90B Counter DRBG (A2907) Page 68 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By Protocol Secrets Secrets used by RADIUS or TACACS+ (8 characters minimum) 8 charact ers minimu m - Authentica tion Data - CSP - CSP Public key for software load test Used to authenticate software and content to be installed on the firewall (RSA 2048 with SHA2- 256) 2048 bits - 112 bits Public Key - PSP - PSP Pre- Loaded Software Load Test RSA Private Keys RSA Private keys for generation of signatures, authentication or key establishment. (RSA 2048, 3072, or 4096-bit) 2048 - 4096 bits - 112 bits - 152 bits Private Key - CSP RSA KeyGen (FIPS18 6-4) (A2907) TLS RSA SigGen RSA Public Keys RSA public keys managed as certificates for the verification of signatures, establishment of TLS, operator authentication and peer authentication . (RSA 2048, 3072, or 4096-bit) 2048 - 4096 bits - 112 bits - 152 bits Public Key - PSP RSA KeyGen (FIPS18 6-4) (A2907) TLS RSA SigVer SNMPv3 Authentica tion Key HMAC-SHA- 1/224/256/384 /512 160 - 512 bits - 160 - Session Key - CSP - CSP KDF SNMP (A2907) Session Authentication (SNMPv3) Page 69 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By Authenticatio n protocol k 512 bits SNMPv3 Authentica tion Secret Used to support SNMPv3 services (Minimum 8 characters) 8 charact ers minimu m - N/A Authentica tion Key - CSP - CSP SNMPv3 Keying Materials Development SNMPv3 Privacy Secret Used to support SNMPv3 services (Minimum 8 characters) 8 charact ers minimu m - N/A Authentica tion Key - CSP - CSP SNMPv3 Keying Materials Development SNMPv3 Session Key Privacy protocol encryption key (AES 128/192/256 CFB) 128 - 256 bits - 128 - 256 bits Session Key - CSP - CSP KDF SNMP (A2907) Session Encryption/Decr yption (SNMPv3) Software integrity verificatio n key Used to check the integrity of all software code (HMAC- SHA2-256 and ECDSA P-256) (Note: This is not considered an SSP) 256 bits - 256 bits Public Key - PSP - Neither Pre- loaded SSH Client Public Key Public RSA key used to authenticate client. (RSA 2048, 3072, and 4096 bits) 2048 - 4096 bits - 112 bits - 152 bits Public Key - PSP - PSP SSH RSA SigVer SSH DHE/ECD HE Private Componen ts Diffie Hellman or EC Diffie- Hellman private (DH 2048 bits - 112 bits Private Key - CSP - CSP KAS- ECC- KeyGen (SSH) KAS- KAS- ECC (SSH) KAS- SSHv2 Keying Materials Development Page 70 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By Group 14, ECDH P-256, ECDH P-384, ECDH P-521) FFC- KeyGen (SSH) FFC (SSH) SSH DHE/ECD HE Public Componen ts Diffie Hellman or EC Diffie- Hellman public component (DH Group 14, ECDH P- 256, ECDH P- 384, ECDH P- 521) 2048 bits - 112 bits Public Key - PSP - PSP KAS- ECC- KeyGen (SSH) KAS- FFC- KeyGen (SSH) KAS- ECC (SSH) KAS- FFC (SSH) SSHv2 Keying Materials Development SSH Host Public Key SSH Host Public Key (RSA 2048, RSA 3072, RSA 4096, ECDSA P- 256, P-384, or P-521) 2048 - 4096 bits - 112 bits - 152 bits Public Key - PSP - PSP SSH ECDSA KeyGen SSH RSA KeyGen SSH ECDSA SigVer SSH RSA SigVer SSH Session Authentica tion Keys Authenticatio n keys used in all SSH connections to the security module's command line interface (HMAC- SHA-1, HMAC- SHA2-256, HMAC- SHA2-512) (160, 256, 512 bits) 160, 256, or 512 bits - 160, 256, or 512 bits Session Key - CSP - CSP KDF SSH (A2907) KAS- ECC (SSH) KAS- FFC (SSH) KAS- ECC- SSC Sp800- 56Ar3 (A2907) KAS- FFC- SSC Sp800- 56Ar3 (A2907) Session Authentication (SSHv2) Page 71 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By SSH Session Encryption Keys Used in all SSH connections to the security module's command line interface. (128, 192, or 256 bits: AES CBC or CTR) (128 or 256 bits: AES GCM) 128 - 256 bits - 128 - 256 bits Session Key - CSP - CSP KDF SSH (A2907) KAS- ECC (SSH) KAS- FFC (SSH) KAS- ECC- SSC Sp800- 56Ar3 (A2907) KAS- FFC- SSC Sp800- 56Ar3 (A2907) Session Encryption/Decr yption (SSH) SSH Shared Secret SSH Shared Secret Diffie Hellman or EC Diffie- Hellman shared secret (DH MODP- 2048, ECDH P-256, ECDH P-384, ECDH P-521) 128 - 512 bits - 128 - 256 bits Shared Secret - CSP KDF SSH (A3453) KAS-ECC (SSH) KAS- FFC (SSH) 128 - 512 bits - 128 - 256 bits Shared Secret - CSP KDF SSH (A2907) KAS-ECC (SSH) KAS-FFC (SSH) TLS DHE/ECD HE Private Componen ts Ephemeral Diffie- Hellman private FFC or EC component 2048 bits - 4096 bits - 112 bits - Private Key - CSP KAS- ECC- KeyGen (TLSv1. 2) KAS- KAS- ECC (TLSv1. 2) KAS- FFC TLSv1.2 Keying Materials Development Page 72 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By used in TLS (DHE 2048, ECDHE P- 256, P-384, P- 521) 152 bits FFC- KeyGen (TLSv1. 2) (TLSv1. 2) TLS DHE/ECD HE Public Componen ts Diffie_Hellma n or EC Diffie- Hellman Ephemeral values used in key agreement (DHE 2048, ECDHE P- 256, P-384, P- 521 2048 bits - 4096 bits - 112 bits - 152 bits Public Key - PSP KAS- ECC- KeyGen (TLSv1. 2) KAS- FFC- KeyGen (TLSv1. 2) KAS- ECC (TLSv1. 2) KAS- FFC (TLSv1. 2) TLSv1.2 Keying Materials Development TLS Encryption Keys AES (128 or 256 bit) keys used in TLS connections (GCM; CBC) 128 - 256 bits - 128 - 256 bits Session Key - CSP - CSP KDF TLS (A2907) KAS- ECC (TLSv1. 2) KAS- ECC- KeyGen (TLSv1. 2) KAS- FFC (TLSv1. 2) KAS- FFC- KeyGen (TLSv1. 2) KAS- ECC- SSC Sp800- 56Ar3 (A2907) KAS- FFC- SSC TLSv1.2 Keying Materials Development Page 73 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By Sp800- 56Ar3 (A2907) TLS HMAC Keys HMAC keys used in TLS connections (HMAC- SHA2- 256/384) ( 256, 384 bits) 256 - 384 bits - 256 - 384 bits Session Key - CSP - CSP KDF TLS (A2907) KAS- ECC (TLSv1. 2) KAS- ECC- KeyGen (TLSv1. 2) KAS- FFC (TLSv1. 2) KAS- FFC- KeyGen (TLSv1. 2) KAS- ECC- SSC Sp800- 56Ar3 (A2907) KAS- FFC- SSC Sp800- 56Ar3 (A2907) Session Authentication (TLSv1.2) TLS Master Secret Secret value used to derive the TLS session keys 384 bits - 384 bits Master Secret - CSP - CSP KDF TLS (A2907) KAS- ECC (TLSv1. 2) KAS- FFC (TLSv1. 2) TLSv1.2 Keying Materials Development Page 74 of 91 Name Description Size - Streng th Type - Category Genera ted By Establis hed By Used By TLS Pre- Master Secret Secret value used to derive the TLS Master Secret along with client and server random nonces 2048 bits; 256 bits, 384 bits, 521 bits - 112 bits; 256 bits, 384 bits, 521 bits Shared Secret - CSP KAS- ECC- SSC Sp800- 56Ar3 (A2907) KAS- FFC- SSC Sp800- 56Ar3 (A2907) KAS- ECC (TLSv1. 2) KAS- FFC (TLSv1. 2) TLSv1.2 Keying Materials Development Table 18: SSP Table 1 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs CA Certificates Peer Public Key Input Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command Page 75 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs encrypted by AES-GCM CO, User Password Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Encrypt ed Zeroizatio n Command DRBG Key RAM:Plainte xt Duration of use Power Cycle / Session Terminati on Entropy Input String:Paired With DRBG Seed:Paired With DRBG V:Paired With DRBG Seed RAM:Plainte xt Duration of use Power Cycle / Session Terminati on Entropy Input String:Paired With DRBG Key:Paired With DRBG V:Paired With DRBG V RAM:Plainte xt Duration of use Power Cycle / Session Terminati on Entropy Input String:Paired With DRBG Seed:Paired With Page 76 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs DRBG Key:Paired With ECDSA Private Keys Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command Power Cycle / Session Terminati on ECDSA Public Key:Paired With ECDSA Public Key Module Public Key Output Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command ECDSA Private Keys:Paired With Page 77 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs Password/Sec ret Input via SSHv2 encrypted by AES-GCM Entropy Input String RAM:Plainte xt Duration of use Power Cycle / Session Terminati on DRBG Seed:Paired With DRBG Key:Paired With DRBG V:Paired With Protocol Secrets Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command Public key for software load test HDD:Plainte xt RSA Private Keys Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command Power Cycle / Session Terminati on RSA Public Keys:Paired With Page 78 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM RSA Public Keys Module Public Key Output Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command RSA Private Keys:Paired With SNMPv3 Authenticati on Key HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command SNMPv3 Authentication Secret:Derived From SNMPv3 Privacy Page 79 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs Secret:Derived From SNMPv3 Authenticati on Secret Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command SNMPv3 Privacy Secret Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command Page 80 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs encrypted by AES-GCM SNMPv3 Session Key HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command SNMPv3 Authentication Secret:Derived From SNMPv3 Privacy Secret:Derived From Software integrity verification key HDD:Plainte xt SSH Client Public Key Password/Sec ret Input via TLSv1.2 encrypted by AES and HMAC Password/Sec ret Input via TLSv1.2 encrypted by AES-GCM Password/Sec ret Input via SSHv2 encrypted by AES and HMAC Password/Sec ret Input via SSHv2 encrypted by AES-GCM HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command SSH DHE/ECDH E Private Components RAM:Plainte xt Duration of use Power Cycle / Session Terminati on SSH DHE/ECDHE Public Components:Paire d With SSH DHE/ECDH E Public Components Peer Public Key Input Module RAM:Plainte xt Duration of use Power Cycle / Session SSH DHE/ECDHE Private Page 81 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs Public Key Output Terminati on Components:Paire d With SSH Host Public Key HDD:Plainte xt RAM:Plainte xt Duration of use (plaintext) Zeroizatio n Command SSH Session Authenticati on Keys RAM:Plainte xt Duration of use Power Cycle / Session Terminati on SSH DHE/ECDHE Public Components:Deri ved From SSH DHE/ECDHE Private Components:Deri ved From SSH Session Encryption Keys RAM:Plainte xt Duration of use Power Cycle / Session Terminati on SSH DHE/ECDHE Public Components:Deri ved From SSH DHE/ECDHE Private Components:Deri ved From SSH Shared Secret RAM:Plainte xt SSH Shared Secret RAM:Plaint ext Until session termination Power Cycle/Sessio n Termination Power Cycle / Session Terminati on TLS DHE/ECDH E Private Components RAM:Plainte xt Duration of use Power Cycle / Session Terminati on TLS DHE/ECDHE Public Components:Paire d With TLS DHE/ECDH Peer Public Key Input Module RAM:Plainte xt Duration of use Power Cycle / Session TLS DHE/ECDHE Private Page 82 of 91 Name Input - Output Storage Storage Duration Zeroizati on Related SSPs E Public Components Public Key Output Terminati on Components:Paire d With TLS Encryption Keys RAM:Plainte xt Duration of use Power Cycle / Session Terminati on TLS Master Secret:Derived From TLS HMAC Keys RAM:Plainte xt Duration of use Power Cycle / Session Terminati on TLS Master Secret:Derived From TLS Master Secret RAM:Plainte xt Duration of use Power Cycle / Session Terminati on TLS Pre-Master Secret:Derived From TLS Pre- Master Secret RAM:Plainte xt Duration of use Power Cycle / Session Terminati on Table 19: SSP Table 2 10 Self-Tests The cryptographic module performs the following tests below. The operator can command the module to perform the pre-operational and cryptographic algorithm self-tests by cycling power of the module. The pre-operational and conditional self-tests are performed automatically and do not require any additional operator action. 10.1 Pre-Operational Self-Tests Verified with HMAC-SHA2-256 and ECDSA P-256. Note: the ECDSA and HMAC-SHA2-256 KATs are performed prior to the Software integrity test. Algorithm or Test Test Properties Test Method Test Type Indicator Details ECDSA SigVer (FIPS186-4) (A2907) P-256 KAT SW/FW Integrity Self-Test successful Signature Verification Page 83 of 91 Algorithm or Test Test Properties Test Method Test Type Indicator Details HMAC-SHA2-256 (A2907) SHA2-256 KAT SW/FW Integrity Self-Test successful Keyed Checksum Table 20: Pre-Operational Self-Tests 10.2 Conditional Self-Tests Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns AES- ECB (A2907) (Decrypt) 128 bits KAT CAST Self-test output message Decrypt After each power-on or via self-test command AES- GCM (A2907) (Decrypt) 256 Bits KAT CAST Self-test output message Decrypt After each power-on or via self-test command AES- GCM (A2907) (Encrypt) 256 Bits KAT CAST Self-test output message Encrypt After each power-on or via self-test command Counter DRBG (A2907) N/A KAT CAST Self-test output message SP 800-90Arev1 Instantiate/Generate/Res eed Known Answer Tests After each power-on or via self-test command ECDSA / KAS- ECC 256 Bit Minimu m PCT PCT System log message s ECDSA / KAS-ECC pairwise consistency test On session ECDSA SigGen (FIPS186 -4) (A2907) 256 Bits KAT CAST Self-test output message Sign After each power-on or via self-test command ECDSA SigVer (FIPS186 256 Bits KAT CAST Self-test output message Verify After each power-on or via Page 84 of 91 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns -4) (A2907) self-test command HMAC- SHA-1 (A2907) 160 Bits KAT CAST Self-test output message Keyed Hash After each power-on or via self-test command HMAC- SHA2- 224 (A2907) 224 Bits KAT CAST Self-test output message Keyed Hash After each power-on or via self-test command HMAC- SHA2- 256 (A2907) 256 Bits KAT CAST Self-test output message Keyed Hash After each power-on or via self-test command HMAC- SHA2- 384 (A2907) 384 Bits KAT CAST Self-test output message Keyed Hash After each power-on or via self-test command HMAC- SHA2- 512 (A2907) 512 Bits KAT CAST Self-test output message Keyed Hash After each power-on or via self-test command KAS- ECC- SSC Sp800- 56Ar3 (A2907) 256 Bits KAT CAST Self-test output message KAS Computation After each power-on or via self-test command KAS- FFC-SSC Sp800- 56Ar3 (A2907) 2048 Bits KAT CAST Self-test output message KAS Computation After each power-on or via self-test command RSA 2048 Bit Minimu m PCT PCT System log message s RSA pairwise consistency test On session Page 85 of 91 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns RSA SigGen (FIPS186 -4) (A2907) 2048 Bits KAT CAST Self-test output message Sign After each power-on or via self-test command RSA SigVer (FIPS186 -4) (A2907) 2048 Bits KAT CAST Self-test output message Verify After each power-on or via self-test command Safe Primes Key Generatio n (A2907) 2048 Bit Minimu m PCT PCT System log message s KAS-FCC pairwise consistency test On session SHA-1 (A2907) 160 Bits KAT CAST Self-test output message Hash After each power-on or via self-test command SHA2- 256 (A2907) 256 Bits KAT CAST Self-test output message Hash After each power-on or via self-test command SHA2- 384 (A2907) 384 Bits KAT CAST Self-test output message Hash After each power-on or via self-test command SHA2- 512 (A2907) 512 Bits KAT CAST Self-test output message Hash After each power-on or via self-test command Software Load Test 2048 Bit SW Load Test SW/F W Load System log message s Software load test on content load On session SP 800- 90B RCT/AP N/A Fault- Detectio n Test CAST Self-test output message Health tests done on entropy source After each power-on or via Page 86 of 91 Algorith m or Test Test Properti es Test Method Test Type Indicato r Details Conditio ns T Health Tests on Entropy Source self-test command SP 800- 135rev1 SSH KDF with SHA-256 N/A KAT CAST Self-test output message SSHv2 with SHA2-256 After each power-on or via self-test command SP 800- 135rev1 TLS 1.2 with SHA-256 KDF N/A KAT CAST Self-test output message TLSv1.2 with SHA2- 256 After each power-on or via self-test command SP 800- 56A Rev 3 Assuranc e Tests N/A Critical Functio ns Critical Functio n System log message s Assurance tests for SP 800-56A Rev3 On session Table 21: Conditional Self-Tests 10.3 Periodic Self-Test Information Algorithm or Test Test Method Test Type Period Periodic Method ECDSA SigVer (FIPS186-4) (A2907) KAT SW/FW Integrity On Demand Manually or Scheduled HMAC-SHA2- 256 (A2907) KAT SW/FW Integrity On Demand Manually or Scheduled Table 22: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES-ECB (A2907) (Decrypt) KAT CAST On Demand Manually or Scheduled Page 87 of 91 Algorithm or Test Test Method Test Type Period Periodic Method AES-GCM (A2907) (Decrypt) KAT CAST On Demand Manually or Scheduled AES-GCM (A2907) (Encrypt) KAT CAST On Demand Manually or Scheduled Counter DRBG (A2907) KAT CAST On Demand Manually or Scheduled ECDSA / KAS- ECC PCT PCT On session On session ECDSA SigGen (FIPS186-4) (A2907) KAT CAST On Demand Manually or Scheduled ECDSA SigVer (FIPS186-4) (A2907) KAT CAST On Demand Manually or Scheduled HMAC-SHA-1 (A2907) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 224 (A2907) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 256 (A2907) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 384 (A2907) KAT CAST On Demand Manually or Scheduled HMAC-SHA2- 512 (A2907) KAT CAST On Demand Manually or Scheduled KAS-ECC-SSC Sp800-56Ar3 (A2907) KAT CAST On Demand Manually or Scheduled KAS-FFC-SSC Sp800-56Ar3 (A2907) KAT CAST On Demand Manually or Scheduled RSA PCT PCT On session On session RSA SigGen (FIPS186-4) (A2907) KAT CAST On Demand Manually or Scheduled RSA SigVer (FIPS186-4) (A2907) KAT CAST On Demand Manually or Scheduled Safe Primes Key Generation (A2907) PCT PCT On session On session SHA-1 (A2907) KAT CAST On Demand Manually or Scheduled Page 88 of 91 Algorithm or Test Test Method Test Type Period Periodic Method SHA2-256 (A2907) KAT CAST On Demand Manually or Scheduled SHA2-384 (A2907) KAT CAST On Demand Manually or Scheduled SHA2-512 (A2907) KAT CAST On Demand Manually or Scheduled Software Load Test SW Load Test SW/FW Load On session On session SP 800-90B RCT/APT Health Tests on Entropy Source Fault-Detection Test CAST On Demand Manually or Scheduled SP 800-135rev1 SSH KDF with SHA-256 KAT CAST On Demand Manually or Scheduled SP 800-135rev1 TLS 1.2 with SHA-256 KDF KAT CAST On Demand Manually or Scheduled SP 800-56A Rev 3 Assurance Tests Critical Functions Critical Function On session On session Table 23: Conditional Periodic Information 10.4 Error States Name Description Conditions Recovery Method Indicator Conditional Pairwise Consistency or Critical Functions Test Failure Module fails a PCT or critical functions test PCT / Critical functions test Reset session System log prints an error message. Conditional Software Load Test Failure Signature verification fails on software load Signature verification failure N/A System prints Invalid image message. Self-Test / Integrity Test Failure Module fails a self-test or integrity test Self-test or Integrity Test failure Reboot Module or Factory Reset FIPS-CC mode failure. failed. Table 24: Error States In the event of a conditional test failure, the module will output a description of the error. Page 89 of 91 10.5 Operator Initiation of Self-Tests Perform a power cycle or via the ‘Self-Tests’ service 11 Life-Cycle Assurance 11.1 Installation, Initialization, and Startup Procedures The vendor provided life-cycle assurance documentation describes configuration management, design, finite state model, development, testing, delivery & operation, end of life procedures, and guidance. For details regarding the approved mode of operation, see “Approved Mode of Operation''. For details regarding secure installation, initialization, startup, and operation of the module, see below. Installation Instructions The module can be retrieved by downloading Panorama_pc-10.2.3-h1from the support site: https://support.paloaltonetworks.com/Support/Index, and a checksum (SHA2-256) is available to ensure the module is correct. Alternatively, the module version can be obtained by running the following commands via CLI (as an authorized administrator): 1. request system software check 2. request system software download version 10.x 3. request system software install version 10.x 4. request restart system Palo Alto Network provides an Administrator Guide for additional information noted in the “References” section of this Security Policy. The following procedure will initialize the modules into the Approved mode of operation: • During initial boot up, break the boot sequence via the console port connection (by pressing the maint button when instructed to do so) to access the main menu. • Select “Continue.” • Select the “Set FIPS-CC Mode” option to initialize the Approved mode. • Select “Enable FIPS-CC Mode”. • When prompted, select “Reboot” and the module will re-initialize and continue into the Approved mode of operation • (FIPS-CC mode). • The module will reboot. • In “FIPS-CC” mode, the console port is available only as a status output port. o Once the module has finished booting, the Crypto Officer can authenticate using the default credentials that come with the module o Once authenticated, the module will automatically require the operator to change their password; and the default credential is overwritten Page 90 of 91 The module will automatically indicate the Approved mode of operation in the following manner: • Status output interface will indicate “**** FIPS-CC MODE ENABLED ****” via the CLI session. • Status output interface will indicate “FIPS-CC mode enabled successfully” via the console port. • The module will display “FIPS-CC” at all times in the status bar at the bottom of the web interface. • The module will display “fips-cc” when “show system info” is entered via the CLI Note: Disabling FIPS-CC mode causes a complete factory reset, which is described in the Zeroization section below. Non-Compliant State Failure to follow the directions in the Approved Mode of Operation above or rules noted in Section 11 will result in the module operating in a non-compliant state, which is considered out of scope of this validation. 11.2 Administrator Guidance The Administrator Guidance can be obtained from Palo Alto Network’s public site: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin 11.3 Non-Administrator Guidance N/A 11.4 Design and Rules In FIPS-CC mode, the following rules shall apply: • When FIPS-CC mode is enabled, the operator shall not install plugins. o Checked via CLI using “show plugins installed” • When FIPS-CC mode is enabled, the operator shall not use TACACS+. RADIUS may be used but must be protected by TLS protocol. o Checked via CLI using “show deviceconfig” command 11.6 End of Life The following procedure will zeroize the module: • Access the module’s CLI via SSH, and command the module to enter maintenance mode; the module will reboot o Note: Establish a serial connection to the console port Page 91 of 91 • After reboot, select “Continue.” • Select “Factory Reset” • The module will perform a zeroization, and provide the following message once complete: o “Factory Reset Status: Success” Note: Following the completion of this procedure, the module will be placed back into an uninitialized state. 12 Mitigation of Other Attacks This module is not designed to mitigate other attacks outside the scope of FIPS 140-3.