Does this mean that Netflix has to have a private TLS key in the box? I wonder how the security of these keys is usually maintained. Interesting engineering/cryptography problem.
This problem might also be an interesting use case for Signed HTTP Exchanges. Sign the video files, then push them to the caching server. The caching server then never possesses the private keys for the connection and also cannot modify the content.