I know this is an old topic but I have struggled getting thru this lately using a GoDaddy cert. Thought I'd pass along my hard won lesson. GoDaddy will send you a bundle (gd_bundle-xx-xx.crt) and another cert with about 10 letters and numbers (123434321a1s2s2.crt). You have to use both or you will get the private key does not match leaf certificate error. Just open these items in notepad and copy the contents into another notepad doc: RSA private key first, then that numbered cert, then the bundle. Then that text file should verify.
When I got down to the kyrtool show keys command, it worked fine, but the certs command cause a PANIC error and crashed Notes with a handle out of range error. I opened a case with IBM on that.
This is some absolutely poor certificate handling that IBM is foisting upon us.