The AD RMS Service Connection Point

The AD RMS Service Connection Point

精选 转载

IronKui 博主文章分类:MCSE

文章标签 AD RMS Service Conne 文章分类 运维

 

The AD RMS Service Connection Point

The Active Directory Rights Management Services (AD RMS) Service Connection Point (SCP) is an object in Active Directory that holds the web address of the AD RMS certification cluster.  AD RMS-enabled applications use the SCP to discover the AD RMS service; it is the first connection point for users to discover the AD RMS web services. 

Only one SCP can exist in your Active Directory forest.  If you try to install AD RMS and an SCP already exists in your forest from a previous AD RMS installation that was not properly deprovisioned, the new SCP will not install properly.  It must be removed before you can establish the new SCP.  A SCP can be viewed using ADSI Edit or LDP.  To view the SCP, connect to the configuration container in ADSI Edit and navigate the following nodes: CN=Configuration [server name], CN=Services, CN=RightsManagementServices, CN=SCP.  You can remove an SCP by using the ADScpRegister.exe tool included in the RMS Administration Toolkit, which you can download from the Microsoft Download Center: http://www.microsoft.com/downloads/details.aspx?familyid=BAE62CFC-D5A7-46D2-9063-0F6885C26B98&displaylang=en The AD RMS Service Connection Point_AD RMS Service Conne .

The AD RMS SCP can be registered automatically during AD RMS installation, or it can be registered after installation has completed.  To register the SCP you must be a member of the local AD RMS Enterprise Administrators group and the Active Directory Domain Services (AD DS) Enterprise Admins group, or you must have been given the appropriate authority.  If the user account installing AD RMS does not have permission to register the SCP you will see and Event ID: 190 in the Event Viewer The AD RMS Service Connection Point_AD RMS Service Conne .  You can manually register the SCP in the AD RMS console.  Open SCP tab in the cluster's Properties box and select the Change SCP check box. 

If a client computer is not located within the Active Directory Forest, you must use registry keys to point the AD RMS client to the AD RMS cluster.  These registry keys are created in HKEY_Local_Machine\Software\Microsoft\MSDRM\ServiceLocation.   Create a key called Activation with the value of http(s)://<your_cluster>/_wmcs/certification where <your_cluster> is the URL of the root cluster used for certification.

If you are registering the SCP from an AD RMS cluster in a child domain you may receive an error stating that SCP registration failed.  In many cases, the registration was successful, but the registration first takes place in the top-level domain and it takes time to replicate to the child domain where the AD RMS cluster checks for the SCP object.  Once the SCP has been replicated to all global catalog servers in the forest, the message will no longer appear.

  • 收藏
  • 评论
  • 举报

上一篇:Dhcp Policy(转)

下一篇:AD委派加域权限

提问和评论都可以,用心的回复会被更多人看到 评论
发布评论
相关文章

举报文章

请选择举报类型

内容侵权 涉嫌营销 内容抄袭 违法信息 其他

具体原因

包含不真实信息 涉及个人隐私

补充说明

0/200

上传截图

格式支持JPEG/PNG/JPG,图片不超过1.9M

已经收到您得举报信息,我们会尽快审核