At the moment, the SSTP server allows selection of a specific certificate to be used for all connections.
This makes running the SSTP server with certificate validation virtually impossible, since the clients expect the CN to match the server connections FQDN or IP to be accepted.
It would be nice to either have the possibility to run multiple server instances on different interfaces, each with its proper certificate, or to allow certificate selection for different interfaces on a single server configuration (a table with interfaces and certificates, including an "all" selection).
At the moment, using multiple interfaces implies using a user/password pair and disabling certificate validation which renders the whole SSTP setup problematic at best, offering no better security than a mppe encrypted password authenticated PTP connection.
Have fun with your MTs...