it is not clear to me how to handle the situation when proxy serves more than one domain. i guess each domain needs its own user (client/server) certificate. i tried to create to run gen_usercert.sh twice, but i got an error message
The stateOrProvinceName field needed to be the same in the CA certificate (X) and the request (Y)
Failed to generate certificate request
i didn't find information in tls support document on how to handle this multiple domain situation.
-- juha