808bits

PAN-OS 11.0 running on PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, and PA-7000 Series NGFWs

FIPS 140-3 certificate #4829 · Palo Alto Networks, Inc. · data as of 2026-08-28
Active. Sunset date 2026-10-10, 42 days away.
Caveat: Interim Validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and Physical Kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4829
StandardFIPS 140-3
Statusactive
Sunset date2026-10-10
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks, Inc. · website
Hardware versions910-000102 with components 910-000185, 910-000169, 910-000183 and 910-000156 with Physical Kit 920-000112 [1], 910-000122 with components 910-000186, 910-000169, 910-000183 and 910-000156 with Physical Kit 920-000119 [1], 910-000223 with components 920-000293, 910-000195, 910-000194 and 910-000204 with Physical Kit 920-000309 [1], [910-000119 and 910-000120] with Physical Kit 920-000185 [1], [910-000125, 910-000131, 910-000132, and 910-000157] with Physical Kit 920-000186 [1], [910-000162, 910-000163, and 910-000164] with Physical Kit 920-000212 [1], [910-000212, 910-000230, 910-000231, and 910-000232] with Physical Kit 920-000454 [1], [910-000241, 910-000242, 910-000243, and 910-000244] with Physical Kit 920-000333 [1], [910-000252, 910-000253, 910-000254, and 910-000255] with Physical Kit 920-000320 [2], [910-000267 and 910-000269] with Physical Kit 920-000392 [1], and [910-000280 and 910-000281] with Physical Kit 920-000455 [1]
Firmware versions11.0.3-h12 [1] and 11.0.6-h2 [2]

Module description

Palo Alto Networks offers a full line of next-generation security appliances. Our platform architecture is based on our single-pass engine, PAN-OS, for networking, security, threat prevention, and management functionality that is consistent across all platforms. The devices differ only in capacities, performance, and physical configuration.

Security level exceptions

  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3453
AES-CCMA3453
AES-CFB128A3453
AES-CTRA3453
AES-GCMA3453
Conditioning Component AES-CBC-MAC SP800-90BA2138
Conditioning Component AES-CBC-MAC SP800-90BA2153
Conditioning Component AES-CBC-MAC SP800-90BA2165
Conditioning Component AES-CBC-MAC SP800-90BA2541
Counter DRBGA3453
ECDSA KeyGen (FIPS186-4)A3453
ECDSA KeyVer (FIPS186-4)A3453
ECDSA SigGen (FIPS186-4)A3453
ECDSA SigVer (FIPS186-4)A3453
HMAC-SHA-1A3453
HMAC-SHA2-224A3453
HMAC-SHA2-256A3453
HMAC-SHA2-384A3453
HMAC-SHA2-512A3453
KAS-ECC-SSC Sp800-56Ar3A3453
KAS-FFC-SSC Sp800-56Ar3A3453
KDF IKEv2A3453
KDF SNMPA3453
KDF SSHA3453
RSA KeyGen (FIPS186-4)A3453
RSA SigGen (FIPS186-4)A3453
RSA SigVer (FIPS186-4)A3453
Safe Primes Key GenerationA3453
Safe Primes Key VerificationA3453
SHA-1A3453
SHA2-224A3453
SHA2-256A3453
SHA2-384A3453
SHA2-512A3453
TLS v1.2 KDF RFC7627A3453

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-10-11InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2025-09-19UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-11

Source documents