1) Strength - always at least 2048 bits, 4096 if speed isn't as critical as security. For your CSR make sure you use SHA256 for signing (http://itigloo.com/security/generate-an-openssl-certificate-...)
As for ciphers, depends on the tradeoff you need for compatibility vs. security; I would consult Mozilla:
https://wiki.mozilla.org/Security/Server_Side_TLS
They also have a handy config generator, depending on what server you're going to use:
https://mozilla.github.io/server-side-tls/ssl-config-generat...
2) For lowest cost and no bullshit, I'd go with CertSimple (https://certsimple.com), or DigiCert (https://digicert.com).
3) As mentioned below, SSLLabs will point out if any of your config is risky. Besides that, you might want to add a 301 URL redirect to your web server to force people to only use SSL and avoid the fatal mistake of someone forgetting to type http_s_.
Have fun!