failed to open RMS protect e-mail with Revocation list enabled template


dear all,

i setting windows 2008 r2 rms server. rms functions working well until trying use rms revocation list.

i created , signed revocation xml guide below: (this doc win2003, applied win2008?)

http://technet.microsoft.com/en-us/library/cc720208%28ws.10%29.aspx

i created rms template revocation xml. revocation list part is empty of course.

if send rms protected mail template. reciepient cannot open email or document. error is:

you not have credential allow open message ...

the debugview trace shows:

===========================

[3860] [msdrm]:+drmenumeratelicense uflags = drm_el_groupidentity,uindex=1
[3860] [msdrm]:-drmenumeratelicense hr=8004cf33
===========================

please kindly help!

attached is my revocation list file:

=========================

<?xml version="1.0" ?>
<xrml xml:space="preserve" version="1.2">
  <body type="license" version="3.0">
    <issuedtime>2010-09-15t06:53</issuedtime>
    <descriptor>
      <object type="revocation-list">
        <id type="ms-guid">{d6373cba-01f1-4f32-ac58-260f580af0f8}</id>
      </object>
    </descriptor>
<issuer>
      <object type="revocation">
        <id type="acsii-tag">external revocation authority</id>
        <name>revocation list name</name>
        <address type="url">https://adrms.myemail.com.sg/_wmcs/tspl_revocation.xml</address>
      </object>
      <publickey><algorithm>rsa</algorithm><parameter name="public-exponent"><value encoding="integer32">65537</value></parameter><parameter name="modulus"><value encoding="base64" size="1024">w/9humr0gr8ioizhdmfltzoah5kmicdb+vmfdtwajvwb8ho9xymchs2ei01rxph7id95xr9kdzcy3t+/a/nexhewfkyt8qynez02h6aqqvprpjpylvd0ybbwgz8yt7uipkeprdstkfu0ijyojnqh1w7lbd23mmschmhu8qt7+ls=</value></parameter></publickey>
    </issuer>
  <revocationlist>
<revoke category="content" type="content-id">
<object type="microsoft office document">
<id type="ms-guid">{8702641d-3512-4aa4-a584-84c703a5b5c0}</id>
</object>
</revoke>
</revocationlist>
</body><signature><algorithm>rsa pkcs#1-v1.5</algorithm><digest><algorithm>sha1</algorithm></digest><value encoding="base64" size="1024">hht51ml05sooj0y6sszshdforqbw7pxdiffxil5xrgy6lxxwuskunp3u2y3gapin1l2hfzgcw+papvwcxyr0nxy/1b/1gbwha1/5elynosus3bs3eismkktazmdplkzezouqkqh/ksbzsh1+nv45efh75y0la0aylodl5n+/6ts=</value></signature></xrml>

======================

hi,


looks worked engineer on the rms support team helped resolve issue.

there error in technet docs

 

"acsii-tag"  should "ascii-tag"

kemper- msft



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group