Since you said "If the client is participating in the TLS handshake it *always* requires the CA to be installed.", then I guess what I want to do is not possible. Can I make Squid send the requests received from the client to the cache peer? (so the cache peer would see the requests coming from the Squid server and not from the client), I think if this is possible then it'd help in my case. -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users