You manage the loaded certificates in that snap-in,
not make them.
To make a cert/key pair to define a DRA one uses
cipher /r option. One then loads the cert info into
the group policy and one logs in as the DRA account
and loads the key into its private certificates store
if one wants to use the DRA to decrypt.