At Web Protection > Filtering Options > Misc > Certificate for End-User Pages
you can upload a trusted certificate, which will be presented to the user in the web proxy blockpages.
You have to enter a hostname there and choose a certificate.
1. Why do you have to enter a hostname? The hostname should be extracted from the certificate.
2. The hostname isn't correctly written to the blockpages e.g. if you enter "fw1.domain.demo" as hostname,
then the blockpage links the css and images files to "passthrough.fw1.domain.demo". Here are the first lines of the blacklist blockpage:
Content blocked