{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "eac627facfe5f552", "cert_id": 5367, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Panorama 10.2 M-200, M-300, M-600 and M-700", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-06", "validation_type": "Initial", "lab": "Leidos Accredited Testing & Evaluation (AT&E) Lab"}], "vendor_url": "http://www.paloaltonetworks.com", "vendor": "Palo Alto Networks Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Roles, services, and authentication: Level 3", "Operational environment: N/A", "Non-invasive security: N/A", "Life-cycle assurance: Level 3", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The Panorama 10.2 running on M-200, M-300, M-600 and M-700 from Palo Alto Networks Inc., hereafter referred to as \"Panorama M-Series\", \"Panorama HW\", \"modules\", or the \"cryptographic modules\" are multi-chip standalone cryptographic modules designed to fulfill FIPS 140-3 level 2 requirements. Panorama M-Series management appliances provide centralized management and visibility of Palo Alto Networks next generation firewalls. From a central location, you can gain insight into applications, users, and content traversing the firewalls. The knowledge of what is on the network, in conjunction with safe application enablement policies, maximizes protection and control while minimizing administrative effort. Your security team can centrally perform analysis, reporting, and forensics with the aggregated data over time, or on data stored on the local firewall.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-08-22", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#14": 2, "#15": 2, "#13": 2, "#18": 2, "#19": 2, "#11": 2, "#12": 2}}, "fips_security_level": {"Level": {"level 2": 1, "Level 1": 1, "Level 8": 1, "Level 2": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 4, "HMAC- SHA-256": 1, "HMAC-SHA- 160": 1, "HMAC- SHA-1": 1, "HMAC-SHA- 160, 256": 1, "SHA2-224": 3, "SHA2-256": 11, "SHA2- 384": 3, "SHA2-512": 5, "SHA-1": 6, "SHA2-384": 4, "SHA-256": 8, "SHA2- 224": 1, "SHA2- 256": 2, "SHA2- 512": 2, "RSA 2048": 11, "RSA 3072": 1, "RSA 4096": 1, "- PKCS 1": 2, "AES-256": 3, "AES-128": 1, "AES-192": 1, "AES 256": 2, "AES 128/192/256": 1, "AES (128": 1, "PKCS 1": 2}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 3, "AES-128": 1, "AES-192": 1, "AES": 44, "AES-": 7}, "CAST": {"CAST": 44}}, "constructions": {"MAC": {"HMAC": 44}}}, "asymmetric_crypto": {"RSA": {"RSA 2048": 11, "RSA 3072": 1, "RSA 4096": 1}, "ECC": {"ECDH": {"ECDH": 9, "ECDHE": 2}, "ECDSA": {"ECDSA": 112}, "ECC": {"ECC": 13}}, "FF": {"DH": {"DH": 3, "Diffie-Hellman": 1, "DHE": 2}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 6}, "SHA2": {"SHA-256": 8}}}, "crypto_scheme": {"MAC": {"MAC": 11}, "KA": {"Key Agreement": 4}}, "crypto_protocol": {"SSH": {"SSH": 177, "SSHv2": 69}, "TLS": {"TLS": {"TLS": 104, "TLSv1.2": 93, "TLS 1.2": 3}}}, "randomness": {"PRNG": {"DRBG": 54}, "RNG": {"RBG": 2}}, "cipher_mode": {"ECB": {"ECB": 1}, "CBC": {"CBC": 2}, "CTR": {"CTR": 3}, "CFB": {"CFB": 1}, "GCM": {"GCM": 15}}, "ecc_curve": {"NIST": {"P-256": 22, "P-384": 24, "P-521": 22}}, "crypto_engine": {}, "tls_cipher_suite": {"TLS": {"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1, "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1}}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 8}, "IBM": {"SSC": 3}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 7, "FIPS186-4": 27, "FIPS 186-4": 8, "FIPS 198-1": 5, "FIPS 180-4": 5, "FIPS 186-2": 1, "FIPS18": 4, "FIPS186": 4}, "NIST": {"SP 800-38A": 3, "SP 800-38D": 1, "SP 800-90A": 1, "SP 800-56A": 6, "SP 800-135": 3, "SP 800-90B": 1}, "PKCS": {"PKCS 1": 2}, "RFC": {"RFC 5288": 1, "RFC 5246": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "in Section 11 will result in the module operating in a non-compliant state, which is considered out of scope of this validation. 11.2 Administrator Guidance The Administrator Guidance can be obtained from": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 1331820, "pdf_is_encrypted": false, "pdf_number_of_pages": 82, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260706103113-04'00'", "/ModDate": "D:20260706103113-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin", "https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/advanced-url-filtering/advanced-url-filtering-administration.pdf"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["AES-GCMA2906", "HMAC-SHA2-512A2906", "HMAC-SHA2-224A2906", "HMAC-SHA2-256A2906", "ECDSA SigGen (FIPS186-4)A2906", "ECDSA KeyVer (FIPS186-4)A2906", "Safe Primes Key GenerationA2906", "RSA SigVer (FIPS186-4)A2906", "AES-CTRA2906", "RSA KeyGen (FIPS186-4)A2906", "SHA2-512A2906", "ECDSA KeyGen (FIPS186-4)A2906", "HMAC-SHA-1A2906", "SHA2-384A2906", "Counter DRBGA2906", "KAS-ECC-SSC Sp800-56Ar3A2906", "SHA2-224A2906", "SHA-1A2906", "KDF SSHA2906", "KAS-FFC-SSC Sp800-56Ar3A2906", "AES-CBCA2906", "KDF TLSA2906", "Safe Primes Key VerificationA2906", "SHA2-256A2906", "ECDSA SigVer (FIPS186-4)A2906", "RSA SigGen (FIPS186-4)A2906", "KDF SNMPA2906", "HMAC-SHA2-384A2906", "AES-CFB128A2906"]}, "extracted_versions": {"_type": "Set", "elements": ["10.2"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "c24aefadbb3dc6cf0f98bd8b134c733d66982e231d4565f4c055041210951532", "txt_hash": "91f78e18743962a5f83b67090b07ec3ef862fba0f3f5ec1c6287361cbaad60a6", "json_hash": null}}}