If you're going to roll your own CA to secure your infrastructure, get in the habit of also creating your own intermediate authority, esp if you're going to do some minimal client certificates. Then you can keep your root ca offsite and never used. IF your stuff get's compromised, then it's a matter of revoking all of your intermediates certs rather than starting over with a completely new CA.