808bits

PAN-OS 10.1 Next-Generation Hardware Firewalls

FIPS 140-3 certificate #4841 · Palo Alto Networks, Inc. · data as of 2026-08-28
Active. Sunset date 2029-10-15, 1143 days away.
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and Physical Kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4841
StandardFIPS 140-3
Statusactive
Sunset date2029-10-15
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPalo Alto Networks, Inc. · website
Hardware versions910-000128 with Physical Kit 920-000084, 910-000147 with Physical Kit 920-000226, [910-000231, 910-000212, 910-000232, and 910-000230] with Physical Kit 920-000454, [910-000120 and 910-000119] with Physical Kit 920-000185, [910-000162, 910-000163, and 910-000164] with Physical Kit 920-000212, [910-000132, 910-000131, 910-000125, 910-000157, 910-000257, and 910-000357] with Physical Kit 920-000186, 910-000223 with components 920-000293, 910-000195, 910-000194, and 910-000204 with Physical Kit 920-000309, 910-000102 with components 910-000137, 910-000136, 910-000156, 910-000256, 910-000356, 910-000183, 910-0000014, 910-000169, 910-000185, 910-000285, 910-000385, and 910-000013 with Physical Kit 920-000112, and 910-000122 with components 910-000137, 910-000136, 910-000156, 910-000256, 910-000356, 910-000183, 910-0000014, 910-000169, 910-000186, 910-000286, 910-000386, and 910-000012 with Physical Kit 920-000119
Firmware versions10.1.5

Module description

Palo Alto Networks offers a full line of next-generation security appliances that range from the PA-220, designed for enterprise remote offices, to the PA-7080, which is a modular chassis designed for high-speed datacenters. The platform architecture is based on our single-pass engine, PAN-OS, for networking, security, threat prevention, and management functionality that is consistent across all platforms. The devices differ only in capacities, performance, and physical configuration.

Security level exceptions

  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2137
AES-CCMA2137
AES-CFB128A2137
AES-CTRA2137
AES-GCMA2137
Conditioning Component AES-CBC-MAC SP800-90BA1791
Conditioning Component AES-CBC-MAC SP800-90BA2138
Conditioning Component AES-CBC-MAC SP800-90BA2153
Conditioning Component AES-CBC-MAC SP800-90BA2165
Counter DRBGA2137
ECDSA KeyGen (FIPS186-4)A2137
ECDSA KeyVer (FIPS186-4)A2137
ECDSA SigGen (FIPS186-4)A2137
ECDSA SigVer (FIPS186-4)A2137
HMAC-SHA-1A2137
HMAC-SHA2-224A2137
HMAC-SHA2-256A2137
HMAC-SHA2-384A2137
HMAC-SHA2-512A2137
KAS-ECC-SSC Sp800-56Ar3A2137
KAS-FFC-SSC Sp800-56Ar3A2137
KDF IKEv2A2137
KDF SNMPA2137
KDF SSHA2137
KDF TLSA2137
RSA KeyGen (FIPS186-4)A2137
RSA SigGen (FIPS186-4)A2137
RSA SigVer (FIPS186-4)A2137
Safe Primes Key GenerationA2137
Safe Primes Key VerificationA2137
SHA-1A2137
SHA2-224A2137
SHA2-256A2137
SHA2-384A2137
SHA2-512A2137

Allowed algorithms

MD5 (Only allowed as the PRF in TLS v1.1 per IG 2.4.A; Message digest used in TLSv1.0 / v1.1 KDF only)

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-10-16InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2025-03-13UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-16

Source documents