When I "Share a layer" in Pro 2.5 to a federated Portal, I get prompted to accept the certificate assigned to the Server computer that is federated with Portal. The pop up indicates that Pro is trying to talk to the fully-qualified domain name of the machine (e.g. ObscureJoke.datacenter.local) running Server.
I expected Pro to talk to Portal (not Server) and let Portal deal with the communications to Server because Portal and Server are federated. I also wasn't expecting a certificate prompt because the public Portal URL I gave Pro routes traffic through a connection that has a CA-signed certificate and that certificate works just fine with the right host name (e.g. example.firstwatch.net).
How do I convince Pro to stop trying to reach behind Portal's back? I don't want to tell all my Pro users to ignore SSL certificate prompts.