It's been a very long time since I've used *nix!
Here's something cobbled together from bits and pieces found elsewhere:
# create a CSR
openssl req -new -newkey rsa:2048 -nodes -keyout mykey.key -out mycsr.csr
# submit the CSR to the Microsoft CA
curl -k -X POST -H "Content-Type: application/x-www-form-urlencoded" \
-d "Mode=newreq&CertRequest=$(cat mycsr.csr)&CertAttrib=CertificateTemplate:WebServer&TargetStoreFlags=0&SaveCert=yes&ThumbPrint=" \
https://your-ca-server/certsrv/certfnsh.asp
# get the certificate
curl -k -X GET "https://your-ca-server/certsrv/certnew.cer?ReqID=<RequestID>&Enc=b64" -o mycert.cer
# Install the cert
openssl x509 -in mycert.cer -out mycert.pem -outform PEM
I'm not at all sure about ASP support anymore.
Be VERY sure about the security of the URL!!!! The very last thing you want is to expose that URL to unauthorized users. Issuing certs that are valid in your organization to individuals (or machines) over which you have no control would be disastrous.
You may find better information in a forum for your version of Linux. You should probably be using the "Windows Server Security" (not Windows Server Powershell) in any further questions in Microsofts' Q&A forums.