Here are some best practices to follow when setting up a new PKI environment.
http://kazmierczak.eu/itblog/2012/08/22/the-dos-and-donts-of-pki-microsoft-adcs/