Key-based renewal
certreq -machine -q -enroll -cert <thumbprint> renew
Enrollment
Locate enterprise CA
a) find out CA name and server
certutil -config - -ping
b) find out more info about CA and CA type
certutil – dump
In the output of the command above we can find out more information about the type of the CA (enterprise/standalone, root/subordinate…. see Types of Certification Authorities)
certutil -cainfo -config <paste the config: line output from certutil -dump> type
Web based enrollment
URL of your Certificate Services server (eg https://ca-server/certsrv).
via Test Lab Guide: Demonstrating Certificate Key-Based Renewal, Renew a certificate, Requesting a certificate from a local certification authority, Test Lab Guide: Demonstrating Certificate Key-Based Renewal, Certification Authority Web Enrollment Guidance