# Unable to browse Internet after outbound HTTPS Inspection certificate renewal on Security Gateways before PBES2 Support

**Product:** HTTPS Inspection  
**Version:** R81 (EOS), R81.10 (EOS), R81.20  
**Last Modified:** 2026-01-21

## Symptoms

- After renewing and importing a new outbound HTTPS Inspection certificate, users behind affected Security Gateways cannot browse the internet. All HTTP and HTTPS traffic times out.
- No SSL or certificate errors appear in SmartConsole.
- Continuous errors appear in _$FWDIR/log/wstlsd.elg_, including failures to load the outbound CA certificate key material (PKCS12).

```
wstls_get_certkey_of_CA: fwPKCS12_2KeyHolder failed: Unexpected digest len 32  
wstls_set_ssl_inspection_outbound_params_info: Loading CA_certKey failed.  
wstls_init_outbound_cptls_params: Failed setting outbound SSL configuration on cptls_params  
wstls_reload_outbound_https_params: init outbound params failed  
wstls_reload_outbound_https_params() failed.  
wstls_reconf: wstls_reload() failed  
wstlsd_reconf_handler: wstls_reconf() failed
```

- The WSTLSD process is unstable and repeatedly restarts.

## Cause

The renewed HTTPS Inspection certificate used PBES2 encryption which is not supported. This caused the WSTLSD process to fail loading the certificate.

## Solution

We're here for you

Please log in / sign in to view solution

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level:** Advanced  
**Status:** Approved by TAC  
**Date Created:** 2026-01-07  
**Last Modified:** 2026-01-21
