Raj,
Each PCA establishes its own policy with regard to such things
as whether a CA must maintain archival records of certificates. Thus
the practice will vary among CAs certified under different PCAs. But,
note my recent message about what is expected to be common practice
for non-repudiation, as it places some of Gary's concerns in a
different light.
Steve
P.S. You win the proofreading award for finding the left-over
reference to Appendix B. That appendix was omitted, over time,
because it was decided to let users locate and read PCA policy
statements as they are cretated, rather than creating a static example
of sample at of the time of RFC publication.