This is all a bit fishy, if the companies own the machines in question then they can self-sign and include their own self-signed certificate in their own machine's certificate stores. If it is BYOD, then ditto, if it is personal machines (for example phones using the wi-fi) then separate them out from the work machines. Getting dodgily signed certificates that will get Google all riled up at you, the Intermediate CA, and the root CA, sounds like a sledgehammer to crack a nut.

