Create the request

  1. Open an MMC window
  2. Add the Certificates snap-in
  3. Expand Certificates then right click on Personal
  4. Select All Tasks then Request New Certificate...
  5. Click Next then select Active Directory Enrollment Policy
  6. Click Next then check the box next to the name of the desired template
  7. Click on Details on the desired template to expand the request information then click Properties
  8. Set the Subject name type drop down to Common name
  9. Set the Subject name value to the FQDN for the certificate then click Add to include the value on the certificate
  10. Set the Alternate name type drop down to DNS name
  11. Set the Alternate name value to the FQDN for the certificate then click Add to include the value on the certificate
  12. Repeat the previous step as necessary to add additional FQDNs to the certificate
  13. Click OK then click Enroll

Export the keypair (optional)

  1. Open an MMC window
  2. Add the Certificates snap-in
  3. Expand Certificates then Certificate Enrollment Requests then Certificates
  4. Right click on the certificate to export and select All tasks... then Export...
  5. Click Next then select Yes, export the private key
  6. Click Next twice
  7. Check the Password box and set a complex password
  8. Click Next 
  9. Specify a file name for the certificate request
  10. Click Next then click Finish