check and help to generate the root CA when run in https interception mode, and install the CA after user's confirmation (Mac only for now)