NOTE: Wildcard certificates are acceptable (for example, *.contoso.com). Additionally, the DNS records for the AD FS infrastructure ...