On each AD server:
Start/Run
Type in "mmc" and hit return
File/Add-Remove Snap In/Certficates/Add/Computer Account
Next/Finish/OK
Expand Certificates/Personal/Certificates
Right click on "Certificates", All Tasks, Request New Certificate, Next
If you have deployed a CA you should be able to choose "Active Directory Enrolment Policy".
Click Next. Select all the options available.
Click Enroll and you are about done.