Generate a CSR from a certreq policy file
This section shows how to generate a Certificate Signing Request (CSR) from a certreq policy file on the computer where you plan to install Microsoft AD CS. Then, it describes how to create a public/private key pair in your Windows account profile after you generate the CSR file. In a later section, the issues a signed certificate from the CSR, for you to associate with the public/private key pair stored in the Windows Certificate Store.
On the computer where you plan to install Microsoft AD CS, open a text editor.
Create a new file, then copy and paste the following content into that file:
Save the file with the .inf extension (such as certreq_policy.inf).
Open either the command prompt or PowerShell.
Go to the directory with the certreq policy .inf file.
Run the following command to generate a certificate signing request (CSR) from the certreq policy .inf file:
Copy the CSR file to the storage medium configured on your .