Confused with multiple levels of TLS certs that want to generate everywhere

Thanks matt. I finally got this working the way I wanted and posted an entry to the Wiki for anyone else wanting to do this in the future.