You can only do it for HTTP, because in HTTPS, it is already to late (the certificate error is already there). Try this solution from chomps:
You’d put this in www-backend. However I have not tested this personally and I am not sure at this point if the redirect really considers the already rewritten host header. Try it.