If anyone wants to play with this capability, OWASP Proxy allows you to simulate it quite easily.
Basically, it uses a CA cert to sign site-specific certs on demand (as encountered). Typically, that CA cert will be self-generated, and self-signed, and would have to be manually imported into the targeted browsers. However, in the scenario in the story, that CA cert would actually already be trusted by the browser, and no manual import step would be required.