OMI Web Client Certificates - Deployment

The web client requires the SMS Root CA as well as the certificate from the Historian.

What would the best practice be to get these deployed to the users?