Tobais,
Actually you can use a certificate issued by your internal CA on the A/V Edge Authentication role, as it's used for corporate user authentication. It should not be the same certicate as the Edge Internal uses, but it's own dedicated cert. You only need public certs on teh Access Edge and Web Conf roles for greatest flexibilty.
Jeff Schertz, PointBridge | MVP | MCITP: Enterprise Messaging | MCTS: OCS