It really depends on your browser. If you want a cert that any out-of-the-box browser will accept, you'll need to pay Veri$ign or another commercial CA some bucks for it. Otherwise, it's a matter of accepting the certificate into each browser that will be using it, and making sure the name matches. The default certificate created by SME uses secure.domain.com for the name, so that's the host name you'd need to be using to avoid errors.