This option is recommended if you don't have your own internal CA or don't want to use a certificate issued by an external ...

This option is recommended if you don't have your own internal CA or don't want to use a certificate issued by an external CA. After installing AD FS, you must manually install the certificate on federation servers and federation service proxies that communicate with this server.