People can disagree all they want about SSL interception in a corporate environment (for good reason), but it's here to stay. When a corporate user downloads Firefox, tries to simply go to Google and gets a cert error page, they're just going to go back to Chrome because the process of exporting your company's CA cert and then importing it into Firefox so you can use the browser is just simply not feasible for most users.