sorry i.m confused.

So you have a stand alone root CA (you cant have a enterprise root as that is depenant on AD) which should also be offline) that you want to communicate with B/C ?

What sort of communication do you want to take place and why ?

sorry if im confused

however CA serivces use RPC and DCOM to communicate so port 135 and random ports greater than 1024.

of course u wil aslo need 443 etc for SSL aswell.