note that the signed certificate presented by the webserver doesn't have to be the same as the CA certificate used to sign the client certificates, or issued by this - you should be able to just drop a normal webserver certificate into your current setup and have it work fine, client certs certified by yourself and server certs issued by a CA.