Offline PKI using 3 Yubikeys and an ARM single board computer (bernat.ch)
An offline PKI enhances security by physically isolating the certificate authority from network threats. A YubiKey is a low-cost solution to store a root certificate. You also need an air-gapped environment to operate the root CA.