DROID only serves HTTP, and does not implement SSL for HTTPS support. Our deployments always use a proxy server to handle HTTPS termination. The :insecure-site setting is only for DROID returning links and redirects that start with https://. It would be good to add this to the documentation.