808bits

WildFire WF-500

FIPS 140-2 certificate #2617 · Palo Alto Networks · data as of 2026-09-15

WildFire WF-500, from Palo Alto Networks, holds FIPS 140-2 certificate #2617 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy

Certificate

Certificate number2617
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks · website
Hardware versionsP/N: 910-000097-00G Rev G; FIPS Kit P/N: 920-000145 Version Rev 00A
Firmware versions7.0.3

Module description

Quoted from the NIST CMVP entry for this certificate.

WildFire WF-500 identifies unknown malware, zero-day exploits, and Advanced Persistent Threats (APTs) through dynamic analysis, and automatically disseminates protection in near real-time to help security teams meet the challenge of advanced cyber-attacks

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (7)

AlgorithmCAVP certificates
AES3475
CVL564, 565, 566, 567
DRBG870
ECDSA713
HMAC2220
RSA1782
SHS2870

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #567, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); NDRNG; MD5; Triple-DES (non-compliant); CAST; ARCFOUR; Blowfish; Camellia; SEED; RC2; RC4; HMAC-MD5; UMAC; HMAC-RIPEMD

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-04-18InitialUL Verification Services, Inc.
2018-02-13UpdateUL Verification Services, Inc.
2020-02-21UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-04-18, 2018-02-13, 2020-02-21

Source documents