sk184451 - Unable to browse Internet after outbound HTTPS Inspection certificate renewal on Security Gateways before PBES2 Support
Unable to browse Internet after outbound HTTPS Inspection certificate renewal on Security Gateways before PBES2 Support
Product: HTTPS Inspection
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2026-01-21
Symptoms
- After renewing and importing a new outbound HTTPS Inspection certificate, users behind affected Security Gateways cannot browse the internet. All HTTP and HTTPS traffic times out.
- No SSL or certificate errors appear in SmartConsole.
- Continuous errors appear in $FWDIR/log/wstlsd.elg, including failures to load the outbound CA certificate key material (PKCS12).
wstls_get_certkey_of_CA: fwPKCS12_2KeyHolder failed: Unexpected digest len 32
wstls_set_ssl_inspection_outbound_params_info: Loading CA_certKey failed.
wstls_init_outbound_cptls_params: Failed setting outbound SSL configuration on cptls_params
wstls_reload_outbound_https_params: init outbound params failed
wstls_reload_outbound_https_params() failed.
wstls_reconf: wstls_reload() failed
wstlsd_reconf_handler: wstls_reconf() failed
- The WSTLSD process is unstable and repeatedly restarts.
Cause
The renewed HTTPS Inspection certificate used PBES2 encryption which is not supported. This caused the WSTLSD process to fail loading the certificate.
Solution
We're here for you
Please log in / sign in to view solution
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: Advanced
Status: Approved by TAC
Date Created: 2026-01-07
Last Modified: 2026-01-21