Hi Gavin,
If you do a search on "htaccess http to https redirect" you can probably find a tutorial at your level...
I know people like to do that (force the change) but I don't. Instead I change the canonical so the bots know it's there and https will automatically get used over time for incoming links from search, and also elsewhere.
Am I missing something? Is there a reason I should be forcing the change?
As a side note, I'm grateful the certs we have work w and w/o the
www... I do some work for my state u's distance program and have had issues in coursespaces where the way the https was implemented and the redirect forced resulted in broken links. This was by educational publishers. I'm not saying your method would, in their case, their cert did not not work both with and w/o www.