Settings to Control Traffic that is not Decrypted

You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action (PoliciesDecryptionAction). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic.
No Decryption Tab Settings
Description
Block sessions with expired certificates
Terminate the SSL connection if the server certificate is expired. This will prevent a user from being able to accept an expired certificate and continuing with an SSL session.
Block sessions with untrusted issuers
Terminate the SSL session if the server certificate issuer is untrusted.

Related Documentation