And I will be nice, since I like long posts that don't force me to have 
to read all the previous ones.

the key, csr, and cert can be anywherethat the webserver can read and 
that the webserver is told to get the m from.

I would suggest they be somewhere the webserver can get them but otehr 
users on the box (or internet) cannot get them, especially the key.  If 
someone else gets the key, your entire security model is compromised and 
you should start all over generating a new key, getting a new cert, etc, 
since anyone with that key can claim to be you.


