Be sure that you've planned your PKI. Then, see Offline Root CA.