You guys are fooling yourself by just using port 443 to access the PP-squid proxies. Not only is the traffic not encrypted, your PP-password is transmitted in the clear. A better solution would be to have openvpn listen to port 443 or exit the company network with ssh.
Not even SSL on Port 443 is save anymore, because many companies have Blue Coat SSL-proxies, which intercept your traffic (MITM).