Offline Root CA and CDP/AIA paths

From: Harkin (nospam_at_dont.send.any.spam.here.gmail.com)
Date: 08/29/05


Date: Mon, 29 Aug 2005 08:26:58 -0500

So I have my offline root CA finally setup and used the CAPolicy.inf file to
make sure that the extensions were not included in the cert. My
understanding is that I should remove the http and ldap lines from the
extensions in the manager and just leave the local path only. A few of the
resources that I have checked (white papers, books,etc) say that I should go
in and modify these paths to point to something that is reachable for the
clients when they get a cert from my ent sub CA. Which one is it?