AD RMS Business-To-Business Requirements for Trusted User Domains
Applies To: Windows Server 2008, Windows Server 2008 R2
A trusted user domain (TUD) allows the AD RMS root cluster to process requests for client licensor certificates or use licenses from users whose rights account certificates (RACs) were issued by a different AD RMS root cluster. You add a trusted user domain by importing the server licensor certificate of the AD RMS cluster that is to be trusted. You can also add trust policies so that AD RMS can process licensing requests for user certificates from a different AD RMS cluster.
Business-to-business is one such type of TUD and is shown in the following diagram. This type of TUD would involve two different companies sharing rights-protected content between them. Before you set up this type of TUD, there are some requirements that must be met.
Business-to-Business Trusted User Domain Requirements
The following table describes the requirements to implement a solution to enable Company A and Company B to share rights-protected information between them. The following components are required in each company.
Solution Component | Detail | Description | Detail Options |
---|---|---|---|
Active Directory Rights Management Services Server Components |
RMS Domain |
|
|
RMS Client Components |
Users protecting and using AD RMS documents |
|
|
Active Directory Components |
Active Directory Forest |
|
|
ISA Server 2006 (optional) |
Integrated Edge Security Gateway |
|
|
Hardware Security Module (HSM) (optional) |
HSM for AD RMS Key Storage |
|
|
DNS Configuration for intranet and extranet pipelines |
Define extranet or intranet server or cluster URLs and create DNS records |
|
|
DNS configuration for revocation pipelines (optional) |
Define Revocation Pipelines and create DNS records |
|
|
SSL certificates (optional – highly recommended) |
SSL certificates are not required but are highly recommended for each AD RMS pipeline. They are required when you deploy with AD FS. |
|
|
Configuration of rrusted user domain trust |
Required to allow information exchange between companies. |
|
|
Configuration Change on IIS Security |
Because there is no Windows trust between both companies, the licensing issuance service must have anonymous access enabled. |
|
|
High Availability (recommended) |
Because AD RMS is a service that will protect critical information, consider having high availability in all components |
|
|