2) set only one virtual with SSL on port 443 with signed cert! 3) on this one virtual set the all other redirects (eg. https://example.com to https://example.com:444) 4) every other virtual, where we want SSL and we have no private IP available, we set some unique port for …

The default port 443 is bound to receive device certificates and cannot be altered to support multiple binding in the same channel. The results were that smart card authentication would not work and users were unaware of what happened since there is no indication of what really happened. if the certificate contains a subject alternative Are there good alternative HTTP ports rather than port 80? There are actually 3 HTTP alternative ports: 591, 8008 and 8080. They are assigned by IANA as "HTTP Alternate", which makes them pretty much as official as it gets. If you run Linux as a non-privileged user (non-root) you can listen to any port above 1024, so 8008 and 8080 are good candidates.