@matigo for internal domains a wildcard cert with a single IP should cover it. Beyond that it gets tricky…
Searching