I am running into an issue where different business units of the company have finer grained security rules which prevent people from accepting / importing / trusting the OOTB Fiddler Root Certificate. Would it be possible for Fiddler to create a new CSR and import the new signed return certificate. This way I can sign the CSR with our internal CA which all hosts within the company have been configured to trust and accept.
If your environment allows arbitrary PCs to request and receive trusted certificates for other hosts, it sounds like the security policy in the environment is completely broken. Why bother using HTTPS at all?