SSLMate [https://sslmate.com] sells SSL certs from the command line for $15.95/year. The sslmate command line tool takes care of properly generating the key and CSR, and properly assembling the certificate bundle containing the chain certificate. Certificates secure both example.com and www.example.com. No more hard-to-use websites or obscure openssl commands. I'm working on a config file generator too, so you'll be able to specify your server software and it will output a secure config for you.
And since the author mentioned out-of-process SSL termination, I'm also the author of titus [https://www.opsmate.com/titus/], an SSL terminator that is so paranoid it stores the private key in an isolated process (which would have been impervious to Heartbleed). It also solves the original IP address problem by using Linux's transparent proxy support - your web server sees the client's actual IP address even though the connection was proxied through titus.