Sorry, I should have said 'Trusted self-signed' CA vs non-Trusted. I was in one enterprise, they use proxy server, when I went to a non-trusted CA server, I got TLS handshaking error; but it worked fine when going to a 'trusted' CA server. And I know my connection on the proxy was not a SSL-Bump. I was trying to see how does the proxy server decide a server is a trusted, vs non-trusted in splice. If I were going to implement this on the squid, how to configure such a policy. thanks. George -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users