Would it be possible to get support for HSTS as more browsers are starting to support it (Chrome, et all)? It's a simple header addition similar to expires.
The particular part of interest is the implementation portion.
Although it's trivial to add it to your application I think it would be nice to add a simple checkbox in the SSL listener page / an area to set the max-age.