Section 3 - Chapter 16 Flashcards
AD RMS Databases
Windows Internal Database (WID) - does not support remote connections, only one server can use the db
SQL 2005 or later running on seperate server, provides ability to load balance, supports remote connects
AD RMS Infrastructure
IIS - provides web services
Message Queueing - ensures transaction coordination in distributed environments
AD RMS Client - access from desktop
AD DS - provides integrated authentication
AD RMS Root Cluster
Installed by default on first AD RMS server
Handles certs and licensing requests
Only one root cluster per forest
Licensing Only servers for a licensing cluster
Clusters only avail if AD RMS db is on a separate server
Root and licensing only clusters independent, cannot load balance jointly
AD RMS and AD FS
Can integrate to extend rights management beyond the firewall
Must establish federation trust before install of AD RMS extension
Service Account must be trusted in each forest
AD RMS Server Enrollment
Self enrolled when created
Creates a server licensor cert (SLC)
AD RMS Administration Roles
AD RMS Enterprise Admins - manage all aspects
Ad RMS Template Admins - read info about infrastructure and list, create, modify, and export rights policy templates
AD RMS Auditors - manage logs and reports
AD RMS Service - contains service account specified on install
AD RMS Admin Group
All groups are local, create global groups and insert them within the local groups
Rights Account Certs
Issued by AD RMS server, identifies trusted entities that can create and publish rights enabled content
Can assign rights and conditions to the content it creates
AD RMS issues publishing license for content that is permanently attached
To view data, user must acces thru AD RMS enabled browser or application
AD RMS Deployments
Single-server - WID db, components local, cannot scale, use in test environments
Internal - multi servers tied to AD DS, seperate server to host db to load balance
Entranet - provides internal services to authorized users outside the network, firewall exceptions and extranet URL on external facing web server needed
Multi-Forest - when there are exisiting partnerships based on AD DS forest trust, SSL cert to each website that hosts AD RMS clusters in each forest, extend forest schema to include AD RMS objects, AD RMS service account must be trusted in each forest
Licensing-only server - assign SSL cert to website hosting AD RMS root cluster and then install the root cluster
AD RMS and AD FS deployment
SSL cert to website hosting AD RMS root cluster
Install root cluster
Prep federated trust relationship
Create claims aware app on resource partner
Assign Generate Security Audit user rights to AD RMS service account
Define extranet cluster URL in AD RMS
Install AD RMS Identity Federation Support
Upgrade RMS to AD RMS
upgrade to latest RMS SP1
backup servers and config db
make sure all enrollment is complete
upgrade to SQL server
clear RMS Message Queuing
upgrade root cluster before upgrading licensing-only server
upgrade all other servers in the RMS cluster
AD RMS and Core Server
Not Supported
AD RMS Web Services Prerequisites
IIS with ASP.Net
Message Queuing
Web Server URL
AD RMS & AD DS Domain
Windows 2000 SP3 or later
AD RMS must be installed in the same domain as its potential users
AD RMS & Domain User Accounts
Email addresses config’d in AD DS
AD RMS Service Account
Member of the Local Admins
Assigned Generate Security Audits user right
AD RMS Installation Account
Local Admin
Enterprise Admin to generate service connection points
Systems Admin on external database
Must not be on a smart card
AD RMS db instance
Create and name db instance
Start SQL Server Browser service before install
AD RMS Install Cert
SSL cert for AD RMS cluster
Self signed cert in testing environment
Trusted external 3rd party, install cert before AD RMS install
AD RMS Cluster Key Protection
Store key in AD RMS config db
AD RMS and DNS Config
Create CNAME records for the root cluster URL and the db server
AD RMS Client OS
Built In: Win 7, Vista & 2008 r2
Download RMS client for 2000, 2003 and XP