Generate a new decryption certificate in Admin UI / Proxy Settings / HTTP Decryption as shown on the following screenshot. See more information in article Decryption of HTTPS Traffic.
After that, install the decryption certificate as trusted all of your proxy clients. This article describes how this is done. Note this step is not optional as the following steps will use the trusted decryption certificate to validate other certificates.