我是否需要在机器 2 和 3 的受信任根中复制 RootCA

Do I need to copy RootCA in machine 2 & 3's trusted root

我的问题,

谢谢!

It this required to copy RootCA certificate to both Machine2 & Machine3's trusted store?

是的,否则机器将无法断言是否信任它颁发的证书。

can I eliminate this steps?

否,但由于它们是域成员,您可以automate distribution of the root certificate via Group Policy通过在针对计算机 2 和 3 的 GPO 中配置以下设置:

Path: Computer Configuration\Policies\Windows Settings\Security Settings\Public Key Policies
Setting: Trusted Root Certification Authorities