In Windows Explorer on the root CA, locate the certificate revocation list you just published. The CRL's default location is:%systemroot%\system32\CertSrv\CertEnroll\<CAname>.crl. Right-click the CRL file and send it to a drive that has portable storage media.
↑ Return to Top
There are several considerations related to building an offline root CA. The following sections link to additional information related to PKI design, offline root CA installation, and frequently asked questions (FAQ).
Kurt L Hudson edited Revision 5. Comment: Added link to PKI Design Brief Overview
Kurt L Hudson edited Revision 4. Comment: fixed typos and corrected upper/lowercase issues
Kurt L Hudson edited Revision 3. Comment: Added information about how to apply Windows Updates to offline CAs
Kurt L Hudson edited Revision 2. Comment: Added some punctuation and clarification
Kurt L Hudson edited Revision 1. Comment: Added more design resources
Kurt L Hudson edited Original. Comment: Fixed the title
Kurt L Hudson edited Revision 19. Comment: Added return to top links
Ed Price - MSFT edited Revision 23. Comment: Added whitespace between lines. Added tags.
Ed Price - MSFT edited Revision 24. Comment: Added whitespace below TOC. Added tags
"Offline root CAs can issue certificates to removable media devices (e.g. floppy disk, USB drive, CD/DVD) and then physically transported to the subordinate CAs..."
Q: Isn't it a bigger security threat to place your certs on a portable media that can be easily lost or stolen, than to allow a secured network to communicate them across the domain?
Ed Price - MSFT edited Revision 26. Comment: Removing "(en-US)" from titles. Adding tags.