Bill, these two issues might very well be related. Since you say you have installed and reinstalled a couple of times, it is likely that a new cert. was generated on installation each time. If you had browsed to the server or connected using Thunderbird with any of the previous installations, they could already have a certificate on record for that hostname and ip address, and now because of your new installation a different cert. is being presented. I believe I have seen in the past with Thunderbird (as well as Firefox) that it just presents a blank screen when you have a bad certificate. Try deleting the old certificates (really ANY certificate with that hostname) from your client machines, then try to connect again.
As to the issue of mail.domain.net vs. domain.net, you could just point your browser or client to domain.net, I suppose. But to really solve that part of the problem I'll have to defer to some of the other experts.
Hey, one for two is a start, eh?
Dan