get the customer to create an internal ssl cert for it using the domain CA
generate a csr and put the server name in the alternate name filed ( will create a cert with the name listed twice)
then install the domain ca cert into the certificate authority trust
once thats done the internally created cert should install