You generally create the CRL, publish it somewhere and then turn off the CA,
yes.

Typically, you put it in the same place you publish your other CRLs.
It basically needs to be in the location where the CDP extension in your
issuing CA certs says it is. That's usually a URL and/or an LDAP path.
--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
"Gunna" <> wrote in message
news:3F4E3790-7706-4908-8131-...
> In PKI if my Root CA is supposed to be offline I assume that the CRL it
> publihses should be put somewhere that is accessable while it is offline
> like
> in AD or on a webserver etc.
>
> Stupid right.
>