Thank you for this lab.
(and yes...it will help a lot, when you will document different server names etc....)
One question I have: After 1 year, when the RootCA is always offline and the published .crl is outdated.......what is to do? Just publish a new crl list from the RootCA and copy this to AD and the webserver?