In Windows Explorer on the root CA, locate the certificate revocation list you just published. The CRL's default location is:%systemroot%\system32\CertSrv\CertEnroll\<CAname>.crl. Right-click the CRL file and send it to a drive that has portable storage media.
↑ Return to Top
There are several considerations related to building an offline root CA. The following sections link to additional information related to PKI design, offline root CA installation, and frequently asked questions (FAQ).
Very good ! :)
Thanks. Also, great links...
"Offline root CAs can issue certificates to removable media devices (e.g. floppy disk, USB drive, CD/DVD) and then physically transported to the subordinate CAs..."
Q: Isn't it a bigger security threat to place your certs on a portable media that can be easily lost or stolen, than to allow a secured network to communicate them across the domain?
Ed Price - MSFT edited Revision 26. Comment: Removing "(en-US)" from titles. Adding tags.