HTTP authentication follows HTTP redirect

Yep, this is intentional. As @Kromey says: the choice to make a redirect is in the hands of the person who controls the original domain. This also makes it somewhat easier for hosting providers to help prospective customers get certificates on the hosting provider beforehand.