To make sure no-one goes of and uses Keycloak in production without HTTPS we should
require SSL by default. To still allow developers to play with Keycloak without having to
configure HTTPS first we should allow non-HTTPS if accessed via localhost only.