FIPS-CC Security Functions- can you trust PAN documentation?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

FIPS-CC Security Functions- can you trust PAN documentation?

L4 Transporter

According to PAN documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/fips-cc-security-functions

 

MS-CHAPv2 is not compatible with FIPS-CC mode. It is recommended to use RADIUS with TLS.

 

However, in my test with my PAN-820 in FIPs mode, it works perfectly with RADIUS PEAP with MSCHAP-v2.

 

Can you even trust PAN documentation?

2 REPLIES 2

Cyber Elite
Cyber Elite

that seems a bit combative 😛

maybe the documentation could do with a little rewording, or the protocol could be removed from configuration options

 

FIPS-CC classifies MS-CHAPv2 as insecure, but this should not mean the protocol becomes unusable. The recommendation is to use a more secure alternative

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

I have to disagree with you a bit here.  If PAN classifies MS-CHAPv2 as insecure, it should have listed PAP as well because PAP is the least secure method, even worse than MS-CHAPv2.  PAP not only sends password (encrypted with weak encryption) along with username in clear-text over the wire.  MS-CHAPv2 does not do that.  And yet, PAP is available in FIPS-CC mode.  Go figure.

 

 

  • 1309 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!