808bits

PAN-OS 10.2 running on PA-220, PA-220R, PA-400 Series, PA-800 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, and PA-7000 Series NGFWs

FIPS 140-3 certificate #4760 · Palo Alto Networks, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5333. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim Validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and Physical Kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4760
StandardFIPS 140-3
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks, Inc. · website
Hardware versions910-000102 with Physical Kit 920-000112 [1], 910-000122 with Physical Kit 920-000119 [1], 910-000128 with Physical Kit 920-000084 [1], 910-000147 with Physical Kit 920-000226 [1], 910-000223 with Physical Kit 920-000309 [1], [910-000119 and 910-000120] with Physical Kit 920-000185 [1], [910-000125, 910-000131, 910-000132, and 910-000157] with Physical Kit 920-000186 [1], [910-000162, 910-000163, and 910-000164] with Physical Kit 920-000212 [1], [910-000212, 910-000230, 910-000231, and 910-000232] with Physical Kit 920-000454 [1], [910-000241, 910-000242, 910-000243, and 910-000244] with Physical Kit 920-000333 [1], and [910-000252, 910-000253, and 910-000254] with Physical Kit 920-000320 [2]
Firmware versions10.2.8-h4 [1] and 10.2.17 [2]
EntropyENT (P)

Module description

Palo Alto Networks offers a full line of next-generation security appliances that range from the PA-220, designed for enterprise remote offices, to the PA-7080, which is a modular chassis designed for high-speed datacenters. The platform architecture is based on our single-pass engine, PAN-OS, for networking, security, threat prevention, and management functionality that is consistent across all platforms. The devices differ only in capacities, performance, and physical configuration.

Security level exceptions

  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2906
AES-CCMA2906
AES-CFB128A2906
AES-CTRA2906
AES-GCMA2906
Conditioning Component AES-CBC-MAC SP800-90BA2138
Conditioning Component AES-CBC-MAC SP800-90BA2153
Conditioning Component AES-CBC-MAC SP800-90BA2165
Conditioning Component AES-CBC-MAC SP800-90BA2541
Counter DRBGA2906
ECDSA KeyGen (FIPS186-4)A2906
ECDSA KeyVer (FIPS186-4)A2906
ECDSA SigGen (FIPS186-4)A2906
ECDSA SigVer (FIPS186-4)A2906
HMAC-SHA-1A2906
HMAC-SHA2-224A2906
HMAC-SHA2-256A2906
HMAC-SHA2-384A2906
HMAC-SHA2-512A2906
KAS-ECC-SSC Sp800-56Ar3A2906
KAS-FFC-SSC Sp800-56Ar3A2906
KDF IKEv2A2906
KDF SNMPA2906
KDF SSHA2906
KDF TLSA2906
RSA KeyGen (FIPS186-4)A2906
RSA SigGen (FIPS186-4)A2906
RSA SigVer (FIPS186-4)A2906
Safe Primes Key GenerationA2906
Safe Primes Key VerificationA2906
SHA-1A2906
SHA2-224A2906
SHA2-256A2906
SHA2-384A2906
SHA2-512A2906

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-08-14InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2025-09-02UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-14

Source documents