No, that should work fine. That's actually what we used to do in the 3.x series. In the 4.0+ releases, we actually try to include a validated SSL authentication file, in case your server can't look one up for Facebook. The setting name is still for the old 3.x release, and needs to be fixed.
Glad you got this working for you though, and we'll re-investigate any issues with our current method.
Thanks,
Alex