To enhance security, a root certification authority (CA) should remain offline except when needed to issue or renew a certificate. ...

To enhance security, a root certification authority (CA) should remain offline except when needed to issue or renew a certificate. When a root CA is offline, certificate revocation list (CRL) publication intervals should be extended beyond the default seven-day period.