Highly recommend webroot mode with something similar to this[1].
Put that into a cronjob together with service nginx reload and automated zero-downtime renewal is up and running.
There may be some regulation (or suggested guidelines) about high-trust sites (like banks) that are vulnerable to phishing requiring EVs. Otherwise using the Google Safe Browsing API (as they plan on doing[1]) will probably work and is automated.
I can't wait to test it out when the Public beta will start. I am currently in the process of deploying a new webserver at work so I will certainly give this a go.
1. not implemented the auto client yet for nginx (which meant stopping the service)
2. the opaque-ness of when my domains would be whitelisted
Both of which will be fixed for public beta/release (I believe).