Ouch... Really sorry!
I think I've made a mistake...
I don't have Pfsense server anymore but i think that It was not External FQDN but reverse https default site witch cares...
And I'm wondering if you don't have to use an host name and not a domains one, something like host.mydomain.com and not only a domain.com...
But My certificate wasn't a wildcard. So it could be wrong.
To be complete there's some points I have to add here:
to get through this issue, I used the console to look at the squids configurations files. it's not so difficult and there can be found the ssl adresses usable to connect
I ve never been able to have everything working as it should with PFsense with squid on it. One colleague of mine tried again with a fresh install of Pfsense to be sure theyre's no artefact of what I did. But for me, as I read it so many times, pfsense does not work fine with squid (we forgot Squid and changed to a commercial solution)