As we know Mircosoft say that *.domain.com (wildcard certificates) is not supported under Lync.
This is also the issue under Lync 2013 preview.
Documentation from Microsoft say's its ok to use wildcard certificates on TMG/UAG reverse proxy.
If you plan to use Polycom with Lync Phone Edition on any versions of Lync, please do not think about useing wildcard certificates. And not on the "frontend server" and on the internal NIC for Edge. This will give you trouble download the certificate to your Polycom device.
For the internal NIC of Edge server and for the "frontend" server use certificate from the PKI server.