It isn't too bad - you can achieve that you want, I hope:
The key is that although you can only have one SSL and one exclusive IP per Subscription, that SSL certificate will then apply to all domains in the Subscription, including the one you actually want it for. So it will then work on that...