MIP SDK尝试使用ADRM和MDE解密RPMSG时出错
我正在尝试解密从我的组织内部收到的RPMSG文件,该文件已加密RMS。我已经安装了广告RMS和MDE。我正在使用MIP SDK用于C#1.11.72版本。
通用消息失败 - “发生一个或多个错误。”但是,在MIP SDK日志中,我看到了:
失败的API调用:File_create_file_handler_async失败了:[nopermissionserror:'接收消息:目标:在目标https://api.aadrm.com/时,在全球查找租户中找不到SLC公共密钥my/v2/enduserlicenss,nopermissionserror.category = unknownant,相关性= 6F5FB43E-4FE8-452C-AD30-3D3E5E479A5C,CORMERELATIONID.DESCRIPTION.DESCRIPTION = DESCRIPTION = pakiteengine = pakiteentEngine'
我不确定此问题是否与此问题有关。关于如何进行诊断的任何建议将非常有帮助。
I am trying to decrypt an rpmsg file received from inside my organization that has been encrypted with RMS. I have installed AD RMS and the MDE. I am using the MIP SDK for C# version 1.11.72.
Decryption fails with a generic message - "One or more errors occurred." However, in the MIP SDK logs, I see this:
Failed API call: file_create_file_handler_async Failed with: [NoPermissionsError: 'Received message: Can't find SLC public key in global lookup tenant when targeting https://api.aadrm.com/my/v2/enduserlicenses, NoPermissionsError.Category=UnknownTenant, CorrelationId=6f5fb43e-4fe8-452c-ad30-3d3e5e479a5c, CorrelationId.Description=ProtectionEngine'
I am not sure what this issue might be related to. Any advice as to how to diagnose would be very helpful.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
使用 AD RMS 还要求您注册 _rmsdisco SRV 记录。否则,SDK 将默认使用 Azure。
https://learn.microsoft。 com/en-us/information-protection/develop/quick-app-adrms#service-discovery
我将考虑向服务发现部分添加一个链接到 AD RMS 详细信息的部分。
发布记录后,您需要使用 FileEngineSettings 对象上的 Identity 属性。 SDK将使用身份中的域名后缀来追踪SRV记录。
如果您的组织有多个电子邮件域,则每个域都需要一个指向 RMS 群集的 SRV 记录。
Using AD RMS requires that you also have registered the _rmsdisco SRV record. Without that, the SDK defaults to using Azure.
https://learn.microsoft.com/en-us/information-protection/develop/quick-app-adrms#service-discovery
I'll look at adding a section to the Service Discovery section that links to the AD RMS details.
Once the record is published, you need to use the Identity property on the FileEngineSettings object. The SDK will use the domain suffix from the identity to chase the SRV record.
If your organization has multiple email domains, you'll need an SRV record for each that points to the RMS cluster.