Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2006

Behind the Scenes with RMS

Your Mission: Distributing Confidential Data to the "Right" Audience
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Implementing Policy Through Templates, RMS Encryption

RMS in B2B Scenarios
Although RMS is designed to protect content for enterprises, you can also use it in business-to-business (B2B) interactions by establishing Use Trusts between RMS installations. You can establish a Use Trust by exporting the SLC from a trusted RMS server and importing it to a trusting RMS Server in another organization. You're not required to establish a trust relationship between AD infrastructures. A user in the organization using the trusting RMS Server can send rights-protected email and documents to a user in the organization with the trusted RMS Server. The recipient of the rights-protected content will launch his or her RMS-aware applications, which will make an EUL request not to the recipient's RMS Server but to the trusting RMS Server. The EUL request contains the RAC issued by the trusted RMS infrastructure and the PL. The trusting RMS Server uses the imported SLC to validate the RAC before checking to make sure the recipient is permitted to access the content, then issues an EUL.

Enterprises that want to communicate with business partners who don't use the RMS technology, can take advantage of the Passport-based RMS Certification Service. This service allows one-way communication from a user with RMS to a user using the Passport-based service. The non-RMS user is required to obtain a Microsoft Passport. With a Passport-issued RAC, the recipient will be able to make an EUL request of the sender's RMS Server. If the RMS Server receiving the request was configured to trust RACs issued by the Passport-based service and the Extranet Cluster URL was configured on the server, it will issue an EUL.

RMS?Trust It
RMS's method of operation has several benefits over other information protection systems, such as pretty good privacy (PGP) and Secure MIME (S/MIME). First, PGP and S/MIME can only guarantee data confidentiality until the data is received by the recipient, who is then free to modify and redistribute it. Second, with systems such as PGP and S/MIME, it's necessary to obtain the recipient's public key or X.509v3 certificate before you can protect content you wish to send them. Last, protecting content for large groups of users using PGP or S/MIME can be impractical because you need to protect the content for each member of the group and send it individually. RMS overcomes all these problems through its unique architecture.

For more information about RMS, visit the Microsoft Web site dedicated to the product, at http://www.microsoft.com/rms. There, you can download the RMS Server and Client software and find tips to help you install and troubleshoot RMS, as well as links to partners who provide complementary services and who have developed their own RMS-aware applications.

John Howie (jhowie@microsoft.com) is Director of the World Wide Services and IT Technical Community for Security at Microsoft. He has more than 15 years of experience in information security and is a CISA, a CISM, and a CISSP.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments
GOOD ARTICLE

vivalencia October 20, 2008 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Learning Path An interview with Microsoft product managers that answers readers RMS questions:
"Customer Ask About Rights Management Services"


For more information about Planning for RMS:
"Windows Rights Management Services"


For more information about Trustworthy Computing:
"Trustworthy Computing"


For more information about using RMS on Windows Server 2003, and pricing and licensing:
"Windows Rights Management Services for Windows Server 2003 Pricing and Licensing Overview"


To download an RMS technical reference guide:
"Rights Management Services (RMS) Service Pack 1 (SP1) Technical Reference"


Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Active Directory (AD) Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

Managing Unix/Linux with Microsoft System Center Operations Manager 2007 Cross Platform Extensions Beta

Addressing the Insider Threat with NetIQ Security and Administration Solutions

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing