Issue cert from Internal CA
1) go to https://pki.canaccord.com/certsrv/
2) Request Certificate > Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
3) paste csr code into box > submit
4) choose "Canaccord Internal Device SSL " template or other appropriate template
if it doesn't show, login to ca1-subca1, grant "enroll" permission to authenticated users
5) download der
Alternatively, if you don't want to generate a CSR first, you can login to any windows computer as admin add the local certificate store snap in
1) mmc > add local certificate store
2) right click personal folder > request new certificate
3) pick a template and fill in the CN and any SAN: