I currently have my subdomain poitning to the DNS name of my NLB (listening on TLS : 443) via a CNAME, i.e.
https:// foo.mydomain.com