{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "ec5ed4cd5e418f59", "cert_id": 5393, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Palo Alto Networks SD-WAN Instant-On Network (ION) Devices ION 1200, ION 1200-S, ION 3200, ION 5200, and ION 9200", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-10", "validation_type": "Initial", "lab": "Gossamer Security Solutions"}], "vendor_url": "http://www.paloaltonetworks.com", "vendor": "Palo Alto Networks, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals and opacity shield installed as indicated in the Security Policy.", "exceptions": ["Operational environment: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The Palo Alto Networks SD-WAN Instant-On Network (ION) Devices (ION 1200, ION 1200-S, ION 3200, ION 5200 and ION 9200) enable the integration of a diverse set of wide area network (WAN) connection types, improve application performance and visibility, enhance security and compliance, and reduce the overall cost and complexity of your WAN.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-07-10", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#1": 1}}, "fips_security_level": {"Level": {"Level 1": 1, "Level 2": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 4, "HMAC-SHA- 1": 2, "HMAC- SHA1": 1, "SHA2-256": 27, "SHA2-384": 14, "SHA2-512": 16, "SHA-1": 9, "SHA2- 512": 1, "SHA1": 1, "SHA2- 256": 5, "RSA 2048": 3, "- PKCS 1": 4, "AES-128": 2, "AES-192": 2, "AES-256": 5, "AES-128/192/256": 1, "DRBG 256": 2, "PKCS 1": 4, "# A3563": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-128": 2, "AES-192": 2, "AES-256": 5, "AES": 11, "AES-": 10}, "CAST": {"CAST": 89}}, "constructions": {"MAC": {"HMAC": 38, "CBC-MAC": 2}}}, "asymmetric_crypto": {"RSA": {"RSA 2048": 3}, "ECC": {"ECDH": {"ECDH": 1, "ECDHE": 57}, "ECDSA": {"ECDSA": 38}}, "FF": {"DH": {"Diffie-Hellman": 2}, "DSA": {"DSA": 3}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 9, "SHA1": 1}}}, "crypto_scheme": {"MAC": {"MAC": 28}}, "crypto_protocol": {"SSH": {"SSH": 51, "SSHv2": 46}, "TLS": {"TLS": {"TLS": 69, "TLSv1.2": 65, "TLS v1.2": 1}}, "IKE": {"IKEv2": 3}}, "randomness": {"PRNG": {"DRBG": 85}, "RNG": {"RBG": 2}}, "cipher_mode": {"CTR": {"CTR": 37}, "GCM": {"GCM": 10}}, "ecc_curve": {"NIST": {"P-256": 42, "P-384": 12, "P-521": 8, "P-224": 4}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 11}, "IBM": {"SSC": 3}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 8, "FIPS186-4": 19, "FIPS 186-4": 10, "FIPS 198-1": 10, "FIPS 180-4": 12}, "NIST": {"SP 800-38A": 6, "SP 800-38D": 2, "SP 800-90A": 2, "SP 800-56A": 2, "SP 800-135": 5, "SP 800-90B": 1}, "PKCS": {"PKCS 1": 4}, "RFC": {"RFC 5288": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 2, "fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation. 4.6 Cryptographic Output Actions": 1, "of the TELs as depicted below and any additional requirement per the site security policy which are out of scope of this Security Policy. The ION 1200 requires 3 tamper evident labels while the ION 1200-C-NA/ION": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 1648896, "pdf_is_encrypted": false, "pdf_number_of_pages": 54, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260710121207-04'00'", "/ModDate": "D:20260710121207-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.paloaltonetworks.com/", "https://docs.paloaltonetworks.com/", "about:blank"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["SHA2-256C170", "AES-CFB128A3563", "ECDSA SigVer (FIPS186-4)A3563", "HMAC-SHA2-384A3565", "HMAC-SHA2-512A3565", "Counter DRBGA3563", "HMAC-SHA2-256A3565", "AES-CBCA3565", "RSA SigVer (FIPS186-4)C170", "KDF SNMPA3563", "SHA2-384A3565", "ECDSA KeyGen (FIPS186-4)A3563", "HMAC-SHA-1A3563", "RSA KeyGen (FIPS186-4)A3563", "KDF SSHA3563", "AES-GCMA3564", "HMAC DRBGA3564", "KDF IKEv2A3563", "SHA-1C170", "AES-ECBA3563", "ECDSA SigGen (FIPS186-4)A3563", "RSA SigGen (FIPS186-4)A3563", "SHA2-512A3565", "AES-CTRA3563", "KAS-ECC-SSC Sp800-56Ar3A3564", "KDF TLSA3564"]}, "extracted_versions": {"_type": "Set", "elements": ["1200", "3200", "5200", "9200"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "0c481c67985c39402e70535f96fe4524bb29a5f310a3b22e29d923e3f1a3adff", "txt_hash": "0820f86f0f2c88043c8fdb8b66d841e8af6bedc95a212e111318cb682249e7ed", "json_hash": null}}}