Thanks for you reply. You are right about the old setting "acl all src 0.0.0.0/0.0.0.0" . I removed it and the warning message has disappeared when the daemon is restarted. Concerning my main issue I don't understand when you suggest "You can present a real non- self-signed certificate to the visitors via http_port. " I already have in my conf --> "https_port 443 accel cert=/path/owa.pem key=/path/ owa.pem defaultsite=exchange_outside vhost" What is the setting you advise me to add in my config ? thx -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/reverse-proxy-and-exchange-2007-tp3321349p3321876.html Sent from the Squid - Users mailing list archive at Nabble.com.