<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS-CC Security Functions- can you trust PAN documentation? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510783#M106268</link>
    <description>&lt;P&gt;I have to disagree with you a bit here.&amp;nbsp; If PAN classifies MS-CHAPv2 as insecure, it should have listed PAP as well because PAP is the least secure method, even worse than MS-CHAPv2.&amp;nbsp; PAP not only sends password (encrypted with weak encryption) along with username in clear-text over the wire.&amp;nbsp; MS-CHAPv2 does not do that.&amp;nbsp; And yet, PAP is available in FIPS-CC mode.&amp;nbsp; Go figure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 14:45:32 GMT</pubDate>
    <dc:creator>dtran</dc:creator>
    <dc:date>2022-08-04T14:45:32Z</dc:date>
    <item>
      <title>FIPS-CC Security Functions- can you trust PAN documentation?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510056#M106152</link>
      <description>&lt;P&gt;According to PAN documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/fips-cc-security-functions" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/fips-cc-security-functions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MS-CHAPv2 is not compatible with FIPS-CC mode. It is recommended to use RADIUS with TLS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in my test with my PAN-820 in FIPs mode, it works perfectly with RADIUS PEAP with MSCHAP-v2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you even trust PAN documentation?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 15:05:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510056#M106152</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2022-07-27T15:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC Security Functions- can you trust PAN documentation?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510764#M106262</link>
      <description>&lt;P&gt;that seems a bit combative &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;maybe the documentation could do with a little rewording, or the protocol could be removed from configuration options&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FIPS-CC classifies MS-CHAPv2 as insecure, but this should not mean the protocol becomes unusable. The &lt;STRONG&gt;&lt;EM&gt;recommendation&lt;/EM&gt;&lt;/STRONG&gt; is to use a more secure alternative&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 10:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510764#M106262</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-08-04T10:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC Security Functions- can you trust PAN documentation?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510783#M106268</link>
      <description>&lt;P&gt;I have to disagree with you a bit here.&amp;nbsp; If PAN classifies MS-CHAPv2 as insecure, it should have listed PAP as well because PAP is the least secure method, even worse than MS-CHAPv2.&amp;nbsp; PAP not only sends password (encrypted with weak encryption) along with username in clear-text over the wire.&amp;nbsp; MS-CHAPv2 does not do that.&amp;nbsp; And yet, PAP is available in FIPS-CC mode.&amp;nbsp; Go figure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-security-functions-can-you-trust-pan-documentation/m-p/510783#M106268</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2022-08-04T14:45:32Z</dc:date>
    </item>
  </channel>
</rss>

