From exchange 2007 and up i always use a multidomain certificate, thats cheaper than a wildcard certificate.
I use mail.domain.com, autodiscover.domain.com and internal.domain.com so that are 3 names in 1 certificate and all ssl options work. Also for autodiscover you have to make an A record.