Just a note about the certificate, putting the site address into CN is considered bad and misleading practice.
But the most problematic issue with this certificate is that it's CA certificate, which means, the server is using CA certificate keys, probably (even, likely) not protected with password. Then smallest security breach will let the attacker have a hold on the CA keys.
Don't do this. Ever.