If the clients are in a different AD you need to export your CA root public certificate. Then create a group policy in the AD that the clients belong to and add your CA public certificate to their trusted root authority certificate list.
... View more