Yes, the PEM file is used *only* for the payment module. The module uses the PEM file to validate your CC processing requests as authorized by you.
Yes, you should follow your host's instructions to generate a CSR to be used when purchasing an SSL certificate. You need the SSL to provide security protection while collecting customers' private information including CC numbers etc.




