Earlier quoted context omitted.
Writeup was too long. We need to know the short and sweet of what to fix.
Update to 1.0.1g, redo all crypto. That is, revoke certs and keys and regenerate.
When you re-key, it will automatically deactivate the previous cert and is free. It also gives you the opportunity to update to SHA-2 or increase the key to 2048 bit, which you should do unless you have unusual and extreme legacy support needs (and must keep SHA-1 a while longer).