WildFire 11.0 WF-500 and WF-500-B
Caveat: Interim Validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy
Certificate
| Certificate number | 4917 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-12-12 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Palo Alto Networks, Inc. · website |
| Hardware versions | 910-000097 with Physical Kit 920-000145, 910-000270 with Physical Kit 920-000318 |
| Firmware versions | 11.0.4 |
Module description
The WildFire 11.0 WF-500 and WF-500-B module identifies unknown malware, zero-day exploits, and Advanced Persistent Threats (APTs) through dynamic analysis, and automatically disseminates protection in near real-time to help security teams meet the challenge of advanced cyber-attacks.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
- Life-cycle assurance: Level 3
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3453 |
| AES-CFB128 | A3453 |
| AES-CTR | A3453 |
| AES-GCM | A3453 |
| Conditioning Component AES-CBC-MAC SP800-90B | A2518 |
| Counter DRBG | A3453 |
| ECDSA KeyGen (FIPS186-4) | A3453 |
| ECDSA KeyVer (FIPS186-4) | A3453 |
| ECDSA SigGen (FIPS186-4) | A3453 |
| ECDSA SigVer (FIPS186-4) | A3453 |
| HMAC-SHA-1 | A3453 |
| HMAC-SHA2-224 | A3453 |
| HMAC-SHA2-256 | A3453 |
| HMAC-SHA2-384 | A3453 |
| HMAC-SHA2-512 | A3453 |
| KAS-ECC-SSC Sp800-56Ar3 | A3453 |
| KAS-FFC-SSC Sp800-56Ar3 | A3453 |
| KDF IKEv2 | A3453 |
| KDF SNMP | A3453 |
| KDF SSH | A3453 |
| RSA KeyGen (FIPS186-4) | A3453 |
| RSA SigGen (FIPS186-4) | A3453 |
| RSA SigVer (FIPS186-4) | A3453 |
| Safe Primes Key Generation | A3453 |
| Safe Primes Key Verification | A3453 |
| SHA-1 | A3453 |
| SHA2-224 | A3453 |
| SHA2-256 | A3453 |
| SHA2-384 | A3453 |
| SHA2-512 | A3453 |
| TLS v1.2 KDF RFC7627 | A3453 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-12-13 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-12-13