The security of your CA and RA machines is vital.
Remember you need to ensure reliability and availability, as well as confidentiality and trustworthiness.
Remember that SSL protects data only while it is in transit - once it has been received and stored, it is no longer encrypted, and so you need to look to other methods to ensure it remains confidential.