It does not have to be. Done correctly, SSL interception can pass through all the errors to the client:
* certificate issues (expiration, domain mismatch, etc.)
* OCSP/CRL verification
* validation of HPKP header
I understand that few vendors may be doing it (I know one which does at least the first 2). Probably the worst offense is choosing the weakest TLS version + cipher to save resources, like using TLS 1.0 because it take less resources to decode/encode than TLS 1.2 + elliptic curve.