808bits

Wildfire 10.2 WF-500 and WF-500-B

FIPS 140-3 certificate #4784 · Palo Alto Networks, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5468. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and Physical Kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4784
StandardFIPS 140-3
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks, Inc. · website
Hardware versions910-000097 with FIPS Kit 920-000145, 910-000270 with FIPS Kit 920-000318
Firmware versions10.2.3-h1
EntropyENT (NP)

Module description

The Wildfire 10.2 WF-500 and WF-500-B from Palo Alto Networks Inc. cryptographic modules designed to identify unknown malware, zero-day exploits, and Advanced Persistent Threats (APTs) through dynamic analysis, and automatically disseminates protection in near real-time to help security teams meet the challenge of advanced cyber-attacks.

Security level exceptions

  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2906
AES-CFB128A2906
AES-CTRA2906
AES-GCMA2906
Conditioning Component AES-CBC-MAC SP800-90BA2518
Counter DRBGA2906
ECDSA KeyGen (FIPS186-4)A2906
ECDSA KeyVer (FIPS186-4)A2906
ECDSA SigGen (FIPS186-4)A2906
ECDSA SigVer (FIPS186-4)A2906
HMAC-SHA-1A2906
HMAC-SHA2-224A2906
HMAC-SHA2-256A2906
HMAC-SHA2-384A2906
HMAC-SHA2-512A2906
KAS-ECC-SSC Sp800-56Ar3A2906
KAS-FFC-SSC Sp800-56Ar3A2906
KDF IKEv2A2906
KDF SNMPA2906
KDF SSHA2906
KDF TLSA2906
RSA KeyGen (FIPS186-4)A2906
RSA SigGen (FIPS186-4)A2906
RSA SigVer (FIPS186-4)A2906
Safe Primes Key GenerationA2906
Safe Primes Key VerificationA2906
SHA-1A2906
SHA2-224A2906
SHA2-256A2906
SHA2-384A2906
SHA2-512A2906

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-08-29InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2025-03-13UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-29

Source documents