I use intermediate certs for my internal CA and do keep those private keys online for quick and easy generation of new certs but the root cert private key only exists in physical form under my control. It's a bit of a pain to convert the root key back into digital form but I only have to do this every couple of years when the intermediate cert expires.
I got into a habit of writing shell scripts for every certificate related task to make it easier. I use the dialog(1) utility to prompt me for input when that's needed. If things are easy, you're more likely to do them.