In my experience, I've built external Nginx as proxy server to all of the cluster nodes, and make the SSL termination in the Nginx. I set the registration address to the vhost name of the nginx. So, full secure of the connection with domain name, no need to change the registration IP, just use the domain that handled by the reverse proxy. Even better, use redundant Nginx using corosync to build HACluster no single point of failure