Talvez seu administrador não goste de NGINX Plus
porque não é código aberto e aceitaria outro produto de código aberto bem mantido. Em seguida, peça a ele que examine o stunnel . Ele é projetado exatamente para suas necessidades.
Citando um exemplo de stunnel em wikipedia (para SMTP, mas isso se ajustaria a suas necessidades):
For example, one could use stunnel to provide a secure SSL connection to an existing non-SSL-aware SMTP mail server. Assume the SMTP server expects TCP connections on port 25. One would configure stunnel to map the SSL port 465 to non-SSL port 25. A mail client connects via SSL to port 465. Network traffic from the client initially passes over SSL to the stunnel application, which transparently encrypts/decrypts traffic and forwards unsecured traffic to port 25 locally. The mail server sees a non-SSL mail client.
The stunnel process could be running on the same or a different server from the unsecured mail application; however, both machines would typically be behind a firewall on a secure internal network (so that an intruder could not make its own unsecured connection directly to port 25).