With regards to the openSSL heartbleed issue and resolution, should I revoke OR re-key my existing SSL cert?
ONCE you have fixed the problem (upgraded openssl), you can re-key your existing SSL cert.
Re-keying effectively issues a new certificate, and your old cert will be revoked automatically.
The other reason to revoke your certificate is if the information on the certificate (other than your keys) changes. This information is public anyway; it is included in the certificate which is handed out to anyone who connects.
Of course, if they have your private key, any information encrypted with that private key may also have been compromised - you may consider forcing a password change for any users who have logged in in the period in question. Especially administrators.