I was able to figure this all out. Here are the answers to my three questions:
This was the correct assumption.
These are generated using the “server” profile and given whichever name I choose.
I had to create the additional host certificate config file and point the CN in that file to my local fully qualified domain name. This config file was then used as an argument for generating the certificates.
CLICK HERE to find out more related problems solutions.