not supported in pveproxy. if you need this, I'd suggest using some kind of reverse proxy and terminating the public-facing TLS with a stapled OCSP response there (you can use the default self-signed certs for the proxy<->cluster connection and pin the cluster CA there)