<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Ashley Moore</title>
	<atom:link href="http://risualblogs.com/blog/author/ashleym/feed/" rel="self" type="application/rss+xml" />
	<link>http://risualblogs.com/blog</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 14:32:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install</title>
		<link>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/</link>
		<comments>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 12:00:40 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://2.412</guid>
		<description><![CDATA[Just a quick post showing how to change the certification pipeline to use SSL after initial install not choosing to secure the URL. This may be the case if you need to request a certificate after initial set up or are waiting on a third party certificate, or just change your mind! The steps to [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/04/11/active-directory-replication-issue-the-dns-server-is-waiting-for-active-directory-domain-services-ad-ds-to-signal-that-the-initial-synchronization-of-the-directory-has-been-completed/' rel='bookmark' title='Permanent Link: Active Directory Replication Issue &ldquo;The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed&rdquo;'>Active Directory Replication Issue &ldquo;The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed&rdquo;</a> <small>We came across an issue recently when we were creating...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/06/14/problem-deploying-lync-monitoring-server-reports/' rel='bookmark' title='Permanent Link: Problem deploying Lync Monitoring Server Reports'>Problem deploying Lync Monitoring Server Reports</a> <small>Whilst running the SSRS on the Archive/ Monitoring Server I...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/04/06/iis-7-0-https-site-doesnt-work-page-cannot-be-displayed/' rel='bookmark' title='Permanent Link: IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;'>IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;</a> <small>Came across an issue recently where after a reboot we...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Just a quick post showing how to change the certification pipeline to use SSL after initial install not choosing to secure the URL. This may be the case if you need to request a certificate after initial set up or are waiting on a third party certificate, or just change your mind! The steps to do this are outlined below:</p>
<p>1. Open IIS on the AD RMS server and edit the bindings, add a binding for HTTPS selecting the certificate to use making sure the name matches your cluster URL.</p>
<p>2. Remove the HTTP binding from the list and do an IIRESET.</p>
<p>3. Close and reopen the AD RMS console and ensure in the centre console both URL’s are using HTTPS.</p>
<p>4. If the SCP has already been published in Active Directory you will need to re-publish it so that clients discover the new HTTP’s certification pipeline.</p>
<p>Good Luck!</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/04/11/active-directory-replication-issue-the-dns-server-is-waiting-for-active-directory-domain-services-ad-ds-to-signal-that-the-initial-synchronization-of-the-directory-has-been-completed/' rel='bookmark' title='Permanent Link: Active Directory Replication Issue &ldquo;The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed&rdquo;'>Active Directory Replication Issue &ldquo;The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed&rdquo;</a> <small>We came across an issue recently when we were creating...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/06/14/problem-deploying-lync-monitoring-server-reports/' rel='bookmark' title='Permanent Link: Problem deploying Lync Monitoring Server Reports'>Problem deploying Lync Monitoring Server Reports</a> <small>Whilst running the SSRS on the Archive/ Monitoring Server I...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/04/06/iis-7-0-https-site-doesnt-work-page-cannot-be-displayed/' rel='bookmark' title='Permanent Link: IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;'>IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;</a> <small>Came across an issue recently where after a reboot we...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM Portal page not displaying</title>
		<link>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/</link>
		<comments>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 21:13:53 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://2.363</guid>
		<description><![CDATA[When deploying the FIM Portal the page is built on WSS 3.0. You may notice that after deploying the Portal you are just displayed by the default WSS 3.0 page when browsing locally or remotely. When you deploy the FIM Service and FIM Portal it actually installs two .wsp’s which style the SharePoint site in [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/04/06/iis-7-0-https-site-doesnt-work-page-cannot-be-displayed/' rel='bookmark' title='Permanent Link: IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;'>IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;</a> <small>Came across an issue recently where after a reboot we...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/03/22/rss-chimney-netdma/' rel='bookmark' title='Permanent Link: RSS, Chimney &amp; NetDMA'>RSS, Chimney &amp; NetDMA</a> <small>Hi,   I was recently on a call with some...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/11/tmg-2010-sp2-released/' rel='bookmark' title='Permanent Link: TMG 2010 SP2 Released'>TMG 2010 SP2 Released</a> <small>Just to let you know TMG 2010 SP2&#160; has been...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>When deploying the FIM Portal the page is built on WSS 3.0. You may notice that after deploying the Portal you are just displayed by the default WSS 3.0 page when browsing locally or remotely.</p>
<p>When you deploy the FIM Service and FIM Portal it actually installs two .wsp’s which style the SharePoint site in accordance to the FIM Portal functionality. Sometimes after initial installation these features are not enabled by default. To enable them navigate to Central Administration &gt; Site Actions &gt; Site Settings &gt; Site Features and select Activate on both ILM2 Pages and FIM Password Reset Pages</p>
<p>You should then be able to navigate to the url locally and remotely and see the normal FIM Portal page</p>
<p>Hope this helps some headaches as there arent too many pointers as to why this happens</p>
<p>Thanks,</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/04/06/iis-7-0-https-site-doesnt-work-page-cannot-be-displayed/' rel='bookmark' title='Permanent Link: IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;'>IIS 7.0 Https site doesn&#8217;t work &lsquo;Page Cannot Be Displayed&rsquo;</a> <small>Came across an issue recently where after a reboot we...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/03/22/rss-chimney-netdma/' rel='bookmark' title='Permanent Link: RSS, Chimney &amp; NetDMA'>RSS, Chimney &amp; NetDMA</a> <small>Hi,   I was recently on a call with some...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/11/tmg-2010-sp2-released/' rel='bookmark' title='Permanent Link: TMG 2010 SP2 Released'>TMG 2010 SP2 Released</a> <small>Just to let you know TMG 2010 SP2&#160; has been...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HRESULT: 0x800f0818 Unable to add/modify Roles or Features through Server Manager or Powershell after installing updates</title>
		<link>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/</link>
		<comments>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/#comments</comments>
		<pubDate>Thu, 11 Aug 2011 14:13:38 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows Server 2008]]></category>

		<guid isPermaLink="false">http://3.937</guid>
		<description><![CDATA[After installing numerous Windows Updates, usually when bringing a newly installed server up to date on patches, you may recieve the following error in server manager: Error: Unexpected error refreshing Server Manager: Exception from HRESULT:0x800F0818d This issue occurs when corrupt .mum or .cat files are present after the extraction and installation process of windows updates. To [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/05/18/windows-2008-r2-sp1-failure-0x800f0818/' rel='bookmark' title='Permanent Link: Windows 2008 R2 SP1 Failure &quot;0x800f0818&rdquo;'>Windows 2008 R2 SP1 Failure &quot;0x800f0818&rdquo;</a> <small>We ran into an issue recently while trying to upgrade...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/02/11/windows-updates-do-not-download-on-server-2003/' rel='bookmark' title='Permanent Link: Windows Updates do not download on Server 2003'>Windows Updates do not download on Server 2003</a> <small>Problem At a customer site that had critical updates to...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/03/30/issues-installing-system-centre-operations-manager-2007-r2-cumulative-update-4-on-a-windows-server-2003-gateway/' rel='bookmark' title='Permanent Link: Issues Installing System Centre Operations Manager 2007 R2 Cumulative Update 4 on a Windows Server 2003 Gateway'>Issues Installing System Centre Operations Manager 2007 R2 Cumulative Update 4 on a Windows Server 2003 Gateway</a> <small>When running the .msi file to install SCOM 2007 R2...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>After installing numerous Windows Updates, usually when bringing a newly installed server up to date on patches, you may recieve the following error in server manager:</p>
<p>Error: Unexpected error refreshing Server Manager: Exception from HRESULT:0x800F0818d</p>
<p>This issue occurs when corrupt .mum or .cat files are present after the extraction and installation process of windows updates.</p>
<p><a href="http://support.risualblogs.com/blog/files/2011/08/unexpected-error-refreshing-server-manager.png"><img src="http://support.risualblogs.com/blog/files/2011/08/unexpected-error-refreshing-server-manager-300x145.png" alt="" width="300" height="145" class="alignnone size-medium wp-image-941" /></a></p>
<p>To reolve this we need to complete a few steps</p>
<p>1. Download and run the Microsoft Update Readiness Tool from http://support.microsoft.com/kb/947821 once it has run check the log in C:WindowsServicingPackagesCheckSUR.log</p>
<p>2. You should see errors resembling:<br />
 CBS MUM Corrupt 0&#215;00000000 servicingPackagesPackage_for_KB978601~31bf3856ad364e35~amd64~~6.0.1.0.mum  Expected file name Package_for_KB978601_server~31bf3856ad364e35~amd64~~6.0.1.0.mum does not match the actual file name </p>
<p>and further down</p>
<p>Unavailable repair files:<br />
servicingpackagesPackage_for_KB978601~31bf3856ad364e35~amd64~~6.0.1.0.mum </p>
<p>3. There may be more than one problematic update so make a note of all of them, you will then need to download these KB&#8217;s and unpack them using the following commands:</p>
<p>Expand -F:* UpdateKB978601.msu C:Directory</p>
<p>This then shows a cat file which also needs to be unpacked:</p>
<p>Expand -F:* UpdateKB978601.CAB C:DirectoryCAB</p>
<p>4. You will need to grab the two files, one extension .mum and one extension .cat, then rename them making sure they are exactly as was displayed in the CheckSUR.log file. You will then need to copy them into the C:WindowsServicingPackages directory overwriting the existing ones.</p>
<p>These steps should resolve the issues and you should be able to add/remove Roles and Features again <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/05/18/windows-2008-r2-sp1-failure-0x800f0818/' rel='bookmark' title='Permanent Link: Windows 2008 R2 SP1 Failure &quot;0x800f0818&rdquo;'>Windows 2008 R2 SP1 Failure &quot;0x800f0818&rdquo;</a> <small>We ran into an issue recently while trying to upgrade...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/02/11/windows-updates-do-not-download-on-server-2003/' rel='bookmark' title='Permanent Link: Windows Updates do not download on Server 2003'>Windows Updates do not download on Server 2003</a> <small>Problem At a customer site that had critical updates to...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/03/30/issues-installing-system-centre-operations-manager-2007-r2-cumulative-update-4-on-a-windows-server-2003-gateway/' rel='bookmark' title='Permanent Link: Issues Installing System Centre Operations Manager 2007 R2 Cumulative Update 4 on a Windows Server 2003 Gateway'>Issues Installing System Centre Operations Manager 2007 R2 Cumulative Update 4 on a Windows Server 2003 Gateway</a> <small>When running the .msi file to install SCOM 2007 R2...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Un-delegate AD Permissions</title>
		<link>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/</link>
		<comments>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/#comments</comments>
		<pubDate>Fri, 20 May 2011 14:09:33 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://3.813</guid>
		<description><![CDATA[Sometimes after delegating permissions to a user or group it may be required to revoke them (maybe the user has left or group belongs to a temporary team of contractors). To do this you cant go through the delegate control wizard and take back the permissions as you would expect so just thought i would [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/03/15/active-sync-some-users-cannot-set-up-smartphones/' rel='bookmark' title='Permanent Link: Active Sync some users cannot set up smartphones'>Active Sync some users cannot set up smartphones</a> <small>We recently had a problem with one of our customers...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/03/25/powershell-to-assign-permissions-to-home-directories/' rel='bookmark' title='Permanent Link: PowerShell to assign permissions to home directories'>PowerShell to assign permissions to home directories</a> <small>I have a situation where user data is migrating from...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/04/28/exchange-powershell-command-to-show-permissions-on-a-particular-or-all-users-mailboxes/' rel='bookmark' title='Permanent Link: Exchange PowerShell command to show permissions on a particular or all users mailboxes'>Exchange PowerShell command to show permissions on a particular or all users mailboxes</a> <small>We had a request recently to list what users have...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Sometimes after delegating permissions to a user or group it may be required to revoke them (maybe the user has left or group belongs to a temporary team of contractors). To do this you cant go through the delegate control wizard and take back the permissions as you would expect so just thought i would put a quick post up showing how to</p>
<p>First of all open ADUC and select view and make sure Advanced Features is checked<br />
<a href="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture.png"><img class="alignnone size-medium wp-image-814" src="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture-300x161.png" alt="" width="300" height="161" /></a></p>
<p>Next right click the OU that you need to remove the delegated permissions from and select properties and then the security tab</p>
<p><a href="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture2.png"><img class="alignnone size-medium wp-image-815" src="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture2-271x300.png" alt="" width="271" height="300" /></a></p>
<p>Here you should be able to see the user/group that you originally delegated permission to. In order to revoke these delegated permissions simply remove them from the ACL</p>
<p>HTH</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/03/15/active-sync-some-users-cannot-set-up-smartphones/' rel='bookmark' title='Permanent Link: Active Sync some users cannot set up smartphones'>Active Sync some users cannot set up smartphones</a> <small>We recently had a problem with one of our customers...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/03/25/powershell-to-assign-permissions-to-home-directories/' rel='bookmark' title='Permanent Link: PowerShell to assign permissions to home directories'>PowerShell to assign permissions to home directories</a> <small>I have a situation where user data is migrating from...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/04/28/exchange-powershell-command-to-show-permissions-on-a-particular-or-all-users-mailboxes/' rel='bookmark' title='Permanent Link: Exchange PowerShell command to show permissions on a particular or all users mailboxes'>Exchange PowerShell command to show permissions on a particular or all users mailboxes</a> <small>We had a request recently to list what users have...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 &#8211; cant create new distribution group</title>
		<link>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/</link>
		<comments>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/#comments</comments>
		<pubDate>Fri, 21 May 2010 14:23:26 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://3.369</guid>
		<description><![CDATA[When trying to create a new distribution group through EMC you may receive the following error message at the end of the wizard: &#160; Error: Couldn&#8217;t find object &#34;UserAccount&#34;. Please make sure that it was spelled correctly or specify a different object. Reason: The recipient UserAccount isn&#8217;t the expected type. Exchange Management Shell command attempted: [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>When trying to create a new distribution group through EMC you may receive the following error message at the end of the wizard:</p>
<p><a href="http://support.risualblogs.com/blog/files/2010/05/image1.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" title="image" border="0" alt="image" src="http://support.risualblogs.com/blog/files/2010/05/image_thumb1.png" width="330" height="287" /></a>&#160;</p>
<p>Error:    <br />Couldn&#8217;t find object &quot;<em>UserAccount</em>&quot;. Please make sure that it was spelled correctly or specify a different object. Reason: The recipient <em>UserAccount</em> isn&#8217;t the expected type. </p>
<p>Exchange Management Shell command attempted:    <br />new-DistributionGroup -Name &#8216;test&#8217; -Type &#8216;Distribution&#8217; –OrganizationalUnit ‘<em>OU</em>’ -SamAccountName &#8216;test&#8217; -Alias &#8216;test&#8217; </p>
<p>The reason for this is that when creating a Distribution Group it tries to add the mailbox of the user creating it as the manager of the Distribution Group and usually the Admin account that creates the Distribution Groups will not be Mailbox enabled. </p>
<p>To get around this you can use the New-DistributionGroup cmdlet with the ManagedBy Parameter:</p>
<p>new-DistributionGroup -Name<strong> <em>&#8216;test</em>&#8216;</strong> -Type<strong> &#8216;<em>Distribution&#8217;</em></strong> –OrganizationalUnit <strong><em>‘YourDomain/Distribution Groups’</em></strong> -SamAccountName<strong><em> &#8216;test&#8217;</em></strong> -Alias<em><strong> &#8216;test&#8217;</strong></em> –ManagedBy ‘<strong><em>MailboxEnabledAccount’</em></strong></p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who can you trust?</title>
		<link>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/</link>
		<comments>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 10:47:23 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.357</guid>
		<description><![CDATA[Any RMS protected content can only be consumed or created within the trust boundaries of the domain. It is sometimes desirable to be able to share protected content with other external parties (Partners etc) so what do you do then? Well there are a number of options available, of which the main three used are: [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Any RMS protected content can only be consumed or created within the trust boundaries of the domain. It is sometimes desirable to be able to share protected content with other external parties (Partners etc) so what do you do then? Well there are a number of options available, of which the main three used are:</p>
<p>TUD – or Trusted User Domain is primarily used when a company with an RMS infrastructure wants to share protected content with another organization with their own RMS infrastructure. In order to do this a traditional Active Directory trust must first be in place, we can then export the SLC public key of the RMS cluster from the domain wanting to consume content and import it on the RMS cluster in the domain wanting to share content. This of course can be replicated both ways so that both sides can open RMS protected content from the other.</p>
<p>TPD – or Trusted Publishing Domain is usually used in one of two scenarios, one where an AD RMS cluster is being decommissioned and replaced. An example might be where forests are being merged and one cluster is taking over the functions of the others. The other scenario might be when a cluster has to issue licenses for content protected by clusters in another forest (can be used for cross forest RMS protected content exchange) To implement this trust you must export the private key of the cluster you are wanting to consolidate and import it into the TPD section of the remaining AD RMS cluster, this is so use licenses can still be acquired for content protected by the decommissioned cluster.</p>
<p>AD FS support for AD RMS – This is an extremely good feature for collaboration with multiple forests where partners do not have their own AD RMS infrastructure or even don&#8217;t have directories based on AD. To implement this solution AD FS must be configured and a federation trust must be in place. You then in AD FS usually create a new claims aware application entry for AD RMS certification URL, you can then define which claims to accept (for AD RMS this is UPN then email) you then do the same for the licensing URL. You must also make sure to add the server role for AD RMS Identity Federation Support and enable federated identity support in the AD RMS console. There are some registry key changes that have to be made on the trusted domain machines (the side without AD RMS) so that the home realm discover works correctly but this can be done via GPO’s*. You will then be able to send and receive RMS protected content from this entity even though they do not have AD RMS implemented!</p>
<ul>
<li>*Registry Key – HKLM/Software/Microsoft/ </li>
<li>Create registry key: MSDRM </li>
<li>Under this create another registry key: Federation </li>
<li>Under this add a string value named: FederationHomeRealm </li>
<li>with a value of: urn:federation:<em>YourDomain</em>.com </li>
</ul>
<p>So as you can see there are many options for expanding your RMS protection outside the boundaries of your domain or forest. Hope you find this useful! <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RMS bootstrapping CRL problems</title>
		<link>http://support.risualblogs.com/blog/2010/04/06/rms-bootstrapping-crl-problems/</link>
		<comments>http://support.risualblogs.com/blog/2010/04/06/rms-bootstrapping-crl-problems/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 10:33:15 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.345</guid>
		<description><![CDATA[Recently had an issue with our internal RMS infrastructure where users were not able to RMS protect any documents, email etc. Going through some troubleshooting I found that clients were not going through the bootstrapping process correctly and therefore were not getting the needed XrML RMS certificates ….. So I was able to browse to [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Recently had an issue with our internal RMS infrastructure where users were not able to RMS protect any documents, email etc. Going through some troubleshooting I found that clients were not going through the bootstrapping process correctly and therefore were not getting the needed XrML RMS certificates …..</p>
<p>So I was able to browse to the certification and license pipelines no problems, AD RMS server was contactable, was seeing the traffic hit the server in the IIS logs some with 403 and 404 errors…Resolution??</p>
<p>If you go to internet options &gt;&gt; Advanced &gt;&gt; Security and then uncheck the two options:</p>
<p>Check for the publishers certificate revocation</p>
<p>Check for the server certificate revocation</p>
<p>Then try and RMS protect content then suddenly bootstrapping process works, you get your certificates and all is good!</p>
<p> The reason for this is if your AD RMS certification and licensing pipelines are using an internal CA to issue a certificate for HTTPS and your client machines cant reach the CRL distribution point it will not allow you to connect! The quick fix is to uncheck the two options specified above and go through the bootstrapping process, you will then be able to protect and consume RMS content. However the correct fix is to ensure the CRL distribution is correct for your CA and accessible for your AD RMS clients <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />    </p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/04/06/rms-bootstrapping-crl-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>To RMS or not to RMS</title>
		<link>http://support.risualblogs.com/blog/2010/03/29/to-rms-or-not-to-rms/</link>
		<comments>http://support.risualblogs.com/blog/2010/03/29/to-rms-or-not-to-rms/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 17:04:17 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.344</guid>
		<description><![CDATA[Want to implement AD RMS but already have file servers full of unprotected content? No problem! With the AD RMS bulk protection tool and File Classification Infrastructure this can be achieved. In FCI we can create classifications based on business impact (based on Key words e.g. private, or regular expressions such as National Insurance numbers [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p><font size="2" face="Verdana">Want to implement AD RMS but already have file servers full of unprotected content? No problem! With the AD RMS bulk protection tool and File Classification Infrastructure this can be achieved. In FCI we can create classifications based on business impact (based on Key words e.g. private, or regular expressions such as National Insurance numbers etc) and have RMS templates applied to classifications as we see fit, oh the power! * This can also continue to apply to additional files uploaded to the file servers each time the File Server Resource Manager rules and file management tasks run (which can run on a schedule) You can also using FCI set a flag to apply to files that have been encrypted with a time stamp and can configure it to send an email to the owner of the file which has been encrypted.</font></p>
<p><img src="http://www.vocrehabga.org/gib/images/class_file_folder_image4.jpg" width="224" height="191" /></p>
<p><font size="2" face="Verdana">Have SharePoint libraries? Again no problem these can be configured to apply protection based on the NTFS permissions on download from the library, it’s all covered! Automation is the new buzz word within RMS and it continues with Exchange 2010’s automatic protection of emails using transport rules to apply pre-defined templates based on email content or recipients.</font></p>
<p><font size="2" face="Verdana">*Note – By default only the Microsoft Office suite and xps viewer file extensions can be RMS protected, however IRM’s can be downloaded for hundreds of other file types so nearly all file extensions can benefit from RMS protection!</font></p>
<p><font size="2" face="Verdana">To RMS or not to RMS? I think the former <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </font></p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/03/29/to-rms-or-not-to-rms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing the application manifest expiry feature from AD RMS clients</title>
		<link>http://support.risualblogs.com/blog/2010/02/10/removing-the-application-manifest-expiry-feature-from-ad-rms-clients/</link>
		<comments>http://support.risualblogs.com/blog/2010/02/10/removing-the-application-manifest-expiry-feature-from-ad-rms-clients/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 11:02:53 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.340</guid>
		<description><![CDATA[Just a quick post to advise Microsoft has now released a KB to remove the application manifest expiry feature in AD RMS. The reason for this is that this legacy feature was previously used to confirm that applications accessing or creating RMS protected content were to be trusted. This was done by applications being signed [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Just a quick post to advise Microsoft has now released a KB to remove the application manifest expiry feature in AD RMS. The reason for this is that this legacy feature was previously used to confirm that applications accessing or creating RMS protected content were to be trusted. </p>
<p>This was done by applications being signed by application signing certs issued by MS. Once the application signing cert expired the application would no longer be trusted to open or create RMS protected content until it was renewed with application updates, which would cause problems and errors between expiring signing certs and application updates!</p>
<p>This can now be controlled by the system administrator rather than by signing certs, administrators can now define applications, or older versions of applications as untrustworthy themselves.</p>
<p>The update to remove this feature is <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=87f72529-d316-42e8-bf77-a46951f66dda&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+MicrosoftDownloadCenter+%28Microsoft+Download+Center%29#tm">KB979099</a> where the update can be found for all RMS client operating systems.</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/02/10/removing-the-application-manifest-expiry-feature-from-ad-rms-clients/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD RMS &#8211; Certificates</title>
		<link>http://support.risualblogs.com/blog/2010/02/03/ad-rms-certificates/</link>
		<comments>http://support.risualblogs.com/blog/2010/02/03/ad-rms-certificates/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 14:30:58 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.326</guid>
		<description><![CDATA[RMS secures data using certificate key pairs, however it does not require PKI which is a common misconception. PKI can be very useful alongside RMS for securing communications between client and server etc however it is not a requirement. The certificates used in RMS are in XrML (Extensible rights Markup Language), those you should be [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>RMS secures data using certificate key pairs, however it does not require PKI which is a common misconception. PKI can be very useful alongside RMS for securing communications between client and server etc however it is not a requirement. The certificates used in RMS are in XrML (Extensible rights Markup Language), those you should be aware of are as follows:</p>
<p><strong>Server Licensor Certificate</strong> – This is the certificate created when RMS is installed on the first server in a cluster, it is a unique certificate to identify itself. If further servers are added to the cluster then the SLC is shared with these. By default in a root cluster this deals with certification by issuing RAC’s and licensing protected content. In particularly large implementations additional licensing servers can be installed which have their own SLC</p>
<p><strong>Machine Certificate</strong> – This is created the first time that a RMS aware application is used and is tied to the hardware of the machine as well as the user login, so multiple Machine certificates can exist on the same machine if multiple users use it. As well as the machine certificate machines receive a unique Lockbox. The Lockbox contains the machines private key and the machine certificate contains the machines public key so the Lockbox is central to all encryption and decryption.</p>
<p><strong>Rights Account Certificate</strong> – This is the certificate which identifies a user and a standard RAC is associated with the computer that the user is logged onto. The SLC issues a RAC to the client the first time they attempt to consume RMS protected content. The RAC contains the key pair and the private key is encrypted by the public key of the machine certificate.</p>
<p><strong>Client Licensor Certificate</strong> – The CLC is created by the root cluster and sent the the client when they try to protect content using RMS aware apps. They have to be connected to the network to receive this but it grants them the right to publish content, even when not connected. Same as the RAC the CLC contains a key pair, its private key is encrypted by the public key of the user who requested it (their RAC) It also contains the public key of the cluster which issued the certificate which is signed by the private key of the cluster. The private key of the CLC signs any Publishing Licences it creates</p>
<p><strong>Publishing Licence</strong> – The PL is created when a client right protects content and specifies what users have access and what access they have. It contains a symmetric key to decrypt the content which is encrypted by the public key of the cluster which issued the PL. </p>
<p><strong>Use License</strong> – This is presented to a client when they attempt to access rights protected content and contains the rights of the authenticated user requesting access. This is tied to the RAC (which identifies the user). The PL will be sent to the Root Cluster along with the users RAC and if access is allowed the cluster will decrypt the symmetric key using its private key and then re-encrypt the symmetric key using the public key of the user. The user will then be able to decrypt and use the rights they have been granted to access the data.</p>
<p>Heavy stuff but hope this can make a little more sense and show how robust AD RMS actually is! Hopefully will follow up with some more information on integration with some well known MS technologies such as Exchange and SharePoint in the near future…</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/02/03/ad-rms-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

