1. Off-line Root CA. This means to disconnect the network cable from the server (where the CA is running), with two options:
a. To keep the server ON, and diconnected from the network.
b. To keep the server OFF diconnected from the networ and placed into a vault.
NOTE. In some literature the term "Disconnected Root CA" is ussed, it is assumed here that it means the same as "Off line Root CA".
There are also some issues related to the CRL signing, since the off-line Root CA can not be "that" active revoking CRLs, therefore:
1. Keep an off-line Root CA and an on-line signing CRL
2. Keep everything off-line
References
http://www.imc.org/ietf-pkix/old-archive-02/msg02609.html
http://www.windowsecurity.com/articles/Microsoft-PKI-Quick-Guide-Part2-Design.html