Currently I have the ability to open certificates on the local server to request a new certificate.

This brings up a couple of options please note the second option is in a different domain to the local server

If I select this second option I'm present with the following:

I'm then looking to add the shown certificate and it all works through this manual process. Surely there is a better way to script these steps as I need to do this process to all devices in this domain. Any suggestions? I've looked at the
certutil options and get-certificate but can't seem to figure out what data goes where into these commands to make it work. It may also be a day of my brain just not working.
Thanks in advance for any help you can give