The key generated by the engine install ended up with a bad CN; it has a 
five-digit number appended to the host name, and no SAN.

I've lived with this through setup, but now I'm getting close to prod use, and 
need to clean up so that it is usable for general consumption. And the SPICE 
HTML client is completely busted due to this; that's a problem because we're 
mostly MacOS on the client side, and the Mac Spice client is unusable for 
normal humans. 

 I'm wary of attempting to regenerate these manually, as I don't have a handle 
on how the keysare used by the various components.

What is the approved method of regenerating these keys?

