Tobin,
Correct, you need to export the cert from your CAS server to install on the ISA server. You need to export the private key with it so be careful to include that checkbox when you do it.
Colin,
You can use your existing wildcard cert for OWA and SMTP but I'm not sure if there are issues with POP and IMAP. I'm going to try to get a final answer on that today and post an update ASAP.
Maay,
You want exchange to be 'aware' of the certificate. Installing it using the shell allows you to easily enable the cert for multiple services. If you have a single server and aren't planning on using anything other than OWA/EAS/RPC-HTTP then you'll be fine using the IIS UI.