Icinga2 with an existing TLS CA

reading through this now: Own CA for Icinga Cluster/API communication?

I notice that my host-cert does have “DNS: mydom.tld” in the SAN, not the FQDN.