Hmm, why is this not working following the rules of [1]. Try to add the following line
Strict-Transport-Security "max-age=31536000; includeSubDomains"
to the nssock_extraheaders (around line 78) in the config file.
[1] https://www.w3.org/TR/upgrade-insecure-requests/#feature-detect