How to apply SSL in Four-Tier Architecture

I installes the BC14 as described in the below blog:
Server1 - SQL
Server2 - NST
Server3 - IIS, Web Server
Client - Browser Client

All are working well with windows authentication. Now I have to change the authentication to NavUserPassword.
So far I understand the Certificate need to be added in IIS in Site Bindings and Certificate Thumbprint need to be added in the service confoguration(customSettings.config).
For NavUserPassword I need to apply SSL, here I am not sure that how many SSL certificate needed (1 or 2) and how to configure?

Manish Sinha
