wseifert
I did it this way: First, a reverse proxy for grommunio, and then there's the layer 4 proxy in opnsense. I enabled that as well. Then it works.
Forgot to mention that with the opnsense caddy reverse proxy you can set the grommunio to get the certificate itself