Product and Software: This article applies to all Aruba controllers and ArubaOS 3.x.0.
Yes, the same certificate can be used for master and local controllers. No wild card certificate is needed.
For captive portal, the DNS resolution of the FQDN as specified in the CN of the certificate is intercepted on the controller (master or local) where the client is connected. The DNS query never goes to the "real" DNS server. It always resolves to the switchip address of the controller that it is connected to.