Hi!
For any signatures that you see firing on decrypted traffic that don’t seem appropriate. You can open a ticket with ET via Feedback or post on https://community.emergingthreats.net/
For the sig that you mentioned above and ones similar we will have updated for today with some extra metadata. For your use case with the sensor being fed decrypted traffic you may want to look for signatures that have metadata “deployment SSLDecrypt” and “tls_state TLSDecrypt”.
This is something we are actively working on from the ET side to try and help customers more easily tune their rulesets effectively so we appreciate any feedback!
JT