/usr/local/opnsense/service/templates/OPNsense/Proxy/squid.conf
sslproxy_cert_error deny all
sslproxy_cert_error allow all
Edit Code: [Select]/usr/local/opnsense/service/templates/OPNsense/Proxy/squid.confFind a line Code: [Select]sslproxy_cert_error deny all, reconfigure it with Code: [Select]sslproxy_cert_error allow allAfter this, restart the appliance, users should get only certificate warning.Repeat after upgrade.
And you will get a fully broken TLS implementation (easy to MITM invisibly to the user).
Unfortunately, true, but I can't force security over business demands, because it stops business in this case.[...]I have other layers of security that are in force, this is serving me only for web trafic filtering, so it is acceptable for me.