Most of the time, folks opt to use the Client Certificate Management task or Client Provisioning Wizard in the EminentWare product to deploy the WSUS signing certificate on all of the client machine. This of course requires that the EminentWare WMI provider is already installed.
As an alternate, you can also use Group Policy to install those certificates. Here are some helpful links from Microsoft:
http://technet.microsoft.com/en-us/library/cc770315(WS.10).aspx
http://msdn.microsoft.com/en-us/library/bb902479(VS.85).aspx
We have a number of customers that have successfully deployed the certificates this way.
John