Well, it seems we were able to use the existing CSR to get the new certificate. After that it was a matter of concatenating the files in the package in the right order (.crt at the top, followed by the three bundle elements), naming it [whatever].pem and installing it as per the manual. All went well (well, it did eventually, after I spotted a typo in my setssl command).
Hoping this info is useful to someone...
--Richard E