Is your Load Balancer able to do SSL termination ? I would rather create two pools in the LB, one for HTTPS and another for HTTP. That will also free up more resources in the proxy system since it would not be doing SSL termination.

In regards to the auth system, I would suggest swauth since I believe keystone is still under development.