The limitation is that you cannot have your SSL based on the host name in the root domain (mydomain.com); It must be located on a subdomain (for example, www.mydomain.com, secure.mydomain.com). This is due to how the DNS system works:
SSL , CNAME . CNAME aliasing RFC.
, , . , : http://www.google.com/search?&q=ssl+on+subdomain+rails
SSL IP- , $100/.