My memory of the whole process is kinda fuzzy, you're probably right about CSRs. Hopefully the private keys were not sent around via unencrypted email.
But the point still stands: the whole process was a nightmare, no automation, error prone, renewal easily forgetable...
The large companies could have had a staff to manage all that. I was just a solo developer managing my own projects, and it was a hassle.