On each AD server:
Start/Run
Type in "mmc" and hit return
File/Add-Remove Snap In/Certficates/Add/Computer Account

Next/Finish/OK
Expand Certificates/Personal/Certificates

Right click on "Certificates", All Tasks, Request New Certificate, Next
If you have deployed a CA you should be able to choose "Active Directory Enrolment Policy".

Click Next. Select all the options available.

Click Enroll and you are about done.