I previously understood that with squid 3.2 end user will be able to see filtered certificate errors and decide whether to accept or reject a certificate. By filtered, I mean, certificate errors found by squid were going to be passed to end user to decide on whether to accept or reject. Is this correct? If yes, can you point me to a configuration. So far, I found verify flag which denys automatically sites with bad certificates. Thanks in advance