Bart, that fixed it. As long as I do what 'cro' suggests and ensure that the login happens under https, any subsequent https request redirects correctly.
Fantastic.
R.