Offline Root CA

Noun · Security & Infosec

Definitions

  1. A root certificate authority kept disconnected from networks except during tightly controlled signing operations so the highest-trust private key is harder to compromise. Offline root CAs are a standard PKI practice because compromise at the root level can invalidate trust across the entire certificate hierarchy.

    In plain English: A top-level certificate authority kept offline for extra protection.

    Example: "The enterprise PKI used an offline root CA and issued day-to-day certificates only from intermediate authorities."

Related Terms