I am changing the Key Length of the Offline ROOT CA from 2048 to 4096 as per best practices for the ROOTCA but my concern was the effect of it on the issued certificates from SubCA to clients. I know there is no change in the SubCA but do I need to change anything else in my environments other than importing the new certificates issued by the ROOT CA into Active Directory?
Offline Root--> From 2048 to 4098
SubCA--> No change.