The server can't be mail.blah.com
The server must have a unique sub-hostname from your domain, most just use e.g. srv1.blah.com.
THEN you crate a user account with the hostname mail.blah.com
AND IF the A record is pointing correcting, the SSL certificate that you create will work.
CWP -> CWP Migration is tricky, it needs port 2304 open for TCP_IN & TCP_OUT.