With OnDemand VPN you can push a HTTP(s) proxy. Apple is awesome.
If a proxy is used to intercept and modify HTTPS traffic, the server certificate used for the connection between the proxy and the client would be invalid (I mean it would not be signed by a CA trusted by the client). Desktop browsers report an error in response to this condition. I don't know about mobile safari.
How do they deal with this?
We pass https traffic as is, we obviously can't look in it or manipulate it.
However most of the products (something like 98%) are on http connections.