That's not really ideal either...one copy of the cert that isn't protected well becomes a master key of sorts for someone already inside your internal network.
Often inside your network you are more concerned with encryption than authentication. If you "just" need encryption over the wire, wildcard cert's are useful.