<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Active Directory Rights Management Services - AD RMS : Troubleshooting</title><link>http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx</link><description>Tags: Troubleshooting</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Microsoft Office 2003 Cannot Open Documents Protected with RMS</title><link>http://blogs.msdn.com/rms/archive/2009/12/13/cannot-open-office-2003-documents-protected-with-rms.aspx</link><pubDate>Sun, 13 Dec 2009 08:26:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9936193</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9936193.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9936193</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9936193</wfw:comment><description>&lt;P&gt;The issue of the inability to open documents protected with AD RMS with Microsoft Office 2003 has now been resolved with a hotfix. You can obtain the hotfix at the following locations:&lt;/P&gt;
&lt;P&gt;Office Client – &lt;A href="http://support.microsoft.com/?kbid=978551" mce_href="http://support.microsoft.com/?kbid=978551"&gt;KB978551&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Word Viewer – &lt;A href="http://support.microsoft.com/?kbid=978558" mce_href="http://support.microsoft.com/?kbid=978558"&gt;KB978558&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Excel Viewer – &lt;A href="http://support.microsoft.com/?kbid=978557" mce_href="http://support.microsoft.com/?kbid=978557"&gt;KB978557&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9936193" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item><item><title>Activate Information Rights Management in SharePoint</title><link>http://blogs.msdn.com/rms/archive/2009/11/23/activating-information-rights-management-irm-in-sharepoint-proxy-gateway-error-correction.aspx</link><pubDate>Mon, 23 Nov 2009 22:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9927578</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9927578.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9927578</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9927578</wfw:comment><description>&lt;P&gt;Recently we had a case where a customer was having some difficulty activating an IRM-protected document library in SharePoint on a server running Windows Server 2008. He got the following error:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Information Rights Management (IRM): There was a problem while trying to activate a rights account certificate.&lt;BR&gt;Unspecified connection error. Try activating again later.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Error value: 8004cf3b&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;A common cause of this error is that the SharePoint server cannot contact the AD RMS server, due to a 502 Proxy Gateway error.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To resolve this issue:&lt;/STRONG&gt; You can set WinHTTP proxy settings on Windows Server 2008 or Windows Server 2008 R2 using the &lt;A href="http://support.microsoft.com/kb/242468" mce_href="http://support.microsoft.com/kb/242468"&gt;Netsh&lt;/A&gt; command-line tool. You can add the AD RMS Server URL to the proxy bypass list on the computer that is running SharePoint to enable it to bootstrap correctly. The following is an example where https://myRmsServer is added to the proxy bypass list:&lt;/P&gt;
&lt;P&gt;netsh winhttp set proxy proxy-server="myProxyServer.mydomain.corp.contoso.com:80" bypass-list= https://myRmsServer&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9927578" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.msdn.com/rms/archive/tags/SharePoint/default.aspx">SharePoint</category></item><item><title>AD RMS and Group Expansion</title><link>http://blogs.msdn.com/rms/archive/2009/09/16/ad-rms-and-group-expansion.aspx</link><pubDate>Wed, 16 Sep 2009 21:57:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9895996</guid><dc:creator>tonytri</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/9895996.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=9895996</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=9895996</wfw:comment><description>&lt;P&gt;We get occasional questions from customers about AD RMS and group expansion across forests. The following are a few links that can help answer your questions concerning group expansion:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The topic &lt;A href="http://technet.microsoft.com/en-us/library/cc747685(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/cc747685(WS.10).aspx"&gt;Deploying RMS Across Forests&lt;/A&gt; contains a thorough explanation of how AD RMS works in a multiple-forest environment: “RMS uses Active Directory to identify users and distribution groups. When an organization’s Active Directory deployment includes multiple forests, RMS uses contact objects to obtain the identities of users and groups that are part of a different forest than the RMS server.”&lt;/LI&gt;
&lt;LI&gt;The topic &lt;A href="http://technet.microsoft.com/en-us/library/cc747637(WS.10).aspx#BKMK_CIF1" mce_href="http://technet.microsoft.com/en-us/library/cc747637(WS.10).aspx#BKMK_CIF1"&gt;Release Notes for Windows Rights Management Services with Service Pack 2&lt;/A&gt; contains a brief description of the group expansion functionality available in Windows RMS SP2: “…group expansion across forests facilitates the ability for RMS to expand Active Directory Universal group membership in a different forest where group memberships are not replicated between two forests…”&lt;/LI&gt;
&lt;LI&gt;Jason Tyler, a senior support engineer, has a post on his blog called &lt;A href="http://blogs.technet.com/rmssupp/archive/2007/05/11/troubleshooting-your-rms-server-and-group-membership.aspx" mce_href="http://blogs.technet.com/rmssupp/archive/2007/05/11/troubleshooting-your-rms-server-and-group-membership.aspx"&gt;Troubleshooting your RMS Server and Group Membership&lt;/A&gt;: “The only time that I usually will get on an RMS server to track things down (once it is setup and provisioned), is when I get a call from someone who says 'I am sending this RMS/IRM protected message to a group, and people in the group cannot open the message'.”&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9895996" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/AD+RMS/default.aspx">AD RMS</category><category domain="http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item><item><title>Cached mode in Outlook 2003 and RMS</title><link>http://blogs.msdn.com/rms/archive/2006/04/25/cached-mode-in-outlook-2003-and-rms.aspx</link><pubDate>Tue, 25 Apr 2006 21:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:583426</guid><dc:creator>rightsmanagement</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rms/comments/583426.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rms/commentrss.aspx?PostID=583426</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rms/rsscomments.aspx?PostID=583426</wfw:comment><description>&lt;P&gt;Imagine this scenario. You are about to catch a plane. You connect to Internet using a Wi-Fi spot on the airport and sync your Outlook. It’s a long flight and you want to catch up on email during the flight. You jump on the place and when the nice airhostess announces that you can use your portable electronic devices, you pull out your laptop and start reading your email. Now imagine you have a RMS-protected email in your Inbox. Since RMS requires the client to present credentials to the RMS server to get a use license before you can consume the content, you are not able to read that important email.&lt;/P&gt;
&lt;P&gt;Here is the solution. If you use Outlook 2003 in &lt;EM&gt;cached&lt;/EM&gt; mode, you can set the Outlook client to automatically license all RMS-protected emails during sync. This way you can ensure that all protected emails in your Inbox have corresponding use licenses downloaded and hence can be viewed. Now you can have a good flight!&lt;/P&gt;
&lt;P&gt;P.S. Outlook in cached mode should do the above automatically. If it is not doing so, the Registry entry that controls this behavior is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hive: HKEY_CURRENT_USER&lt;/LI&gt;
&lt;LI&gt;Key: Software\Microsoft\Office\11.0\Outlook&lt;/LI&gt;
&lt;LI&gt;Type: REG_DWORD&lt;/LI&gt;
&lt;LI&gt;Entry: UserData&lt;/LI&gt;
&lt;LI&gt;Value: 0x00000001&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If this is not set, or the entry doesn’t exist, create it and logoff and log back on.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=583426" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rms/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item></channel></rss>