I've also done something similar on EC2, with two different load balancers both forwarding to the same instance, but to different ports. Of course then you could also just handle the SSL on the ELB level, but sometimes it's handy to pass it all the way to your web servers.