I have not done anything with Option 2, so no help there.
Choose the Provider of your choice. Many of my clients use: Thawte and Network Solutions
Here is a link you will need to perform the steps - https://www-10.lotus.com/ldd/dominowiki.nsf/dx/3rd_Party_SHA-2_with_OpenSSL_and_kyrtool?open
I had one client use a wildcard, this was a bit tricky, since the steps needed to to be performed, wanted a cert with the Private key in is, with did not seem to be extractable from the cert the provider initially sent. We got it done and were set for all of their servers.
Walt