The CA is accessible in every computer connected to the domain
Open the Microsoft Management Console:
Windows > run.exe > mmc
Display the certificate Component
File > Add/Remove Snap-in Add “Certificates” and click “ok”

By exploring :
- Certificates > Current User
- Root Certification Authorities
- Certificates
- Root Certification Authorities
We find the domain CA.
