I have a long standing TAC case open on VPN certificate problems on the SMBs. It's really odd that we are still seeing issues with certificates on these (or any) devices.
In my case installing a .p12 certificate bundle for vpn.domain.com on the device, and renewing it had problems. It can be re-done (remove everything, reboot box, and re-install) but this really should NOT be required IMHO.
Of course then when the certificate is actually installed and functioning, the VPN sometimes suddenly fails to see it and stops using the certificate for VPNs causing them to fail.
I have had this issue on newer firmware R81.10.10, R81.10.15, and has finally reached a threshold of 30% failures with one of my clients.