The send connector in Exchange 2010 SP1 will be configured with each DLP endpoint as a smart host. The authentication should be set to none. When using certificates to verify identity during a TLS sesson you will still se the Exchange send connector authentication to none.
Using the SMTP log on Exchange and DLP the certificate is exchanged during the TLS SMTP sesssion.
The DLP cert must be in the Exchange Root Trusted store The Exchang hub selfsinged scerts must be in the DLP trusted store.