You don’t need to establish any rules but you do need to make sure the server is properly configured to serve your site on a valid certificate. With a 525 that won’t be the case and is the first thing you need to address with your host as you need a proper certificate on your server in the first place.
Ideally you’d make sure you have a valid certificate for the naked domain as well, but if that does not work for any reason the next best approach would be to redirect to “www”.
Just make sure your encryption mode is “Full strict”.