Most organizations deploy an offline root certification authority (CA) and one or more subordinate CAs as a public key infrastructure ...

Most organizations deploy an offline root certification authority (CA) and one or more subordinate CAs as a public key infrastructure (PKI). After these CAs have been installed on servers, a number of follow-up steps must be completed before the PKI can be used to issue, support, and manage certificates. These follow-up tasks involve setting up certificate revocation options, configuring certificates or certificate templates, and configuring enrollment and issuance options.