On Monday 13 June 2016 at 10:51:35, Eng Hooda wrote:

> Thank You for your response.
> Using the certificate is something I want to avoid.
> So I think it's acceptable as it is now.
> I searched again and found an explanation , copied below FYI.
> "To serve an HTTP error to an SSL client, Squid has to establish an SSL
> connection with that client."

Yes, but the point is that the client originally requested an SSL connection 
to a particular server, and if it gets a reply (even though it is an SSL 
reply) back from something with a certificate which doesn't match that server, 
the client will complain, showing a security alert to the user.


