Upgrade from RMS to AD RMS
The following list contains known issues when upgrading from RMS on Windows Server 2003 to Usługi AD RMS on Windows Server 2008:
- Usługi AD RMS requires that the service account be a domain user account. If RMS has been using the local SYSTEM account for the service account, you will need to specify a domain user account during the upgrade to Usługi AD RMS.
- You should clear the RMS MSMQ message queue before upgrading to Windows Server 2008.
- If RMS was provisioned using a hardware security module (HSM), you must reinstall the HSM drivers after the upgrade to Windows Server 2008 is complete, but before you start the upgrade to Usługi AD RMS.
- If you are using a port other than 80 to host your RMS cluster, the Usługi AD RMS Upgrade Wizard will bind two ports to this Web site during the upgrade. You must remove the incorrect binding and restart Internet Information Services before the Usługi AD RMS cluster can service requests.
- Custom access control lists (ACLs) that are applied to the Admin and GroupExpansion virtual directories are not migrated during the upgrade. If you have a custom ACL on either of these directories, you must set them up manually after the upgrade.
- After completing the upgrade to Usługi AD RMS, you may receive the following error when opening the Active Directory Rights Management Services console:
A connection with the specified Usługi AD RMS cluster could not be established. Cannot read configuration file due to insufficient permissions.
You must restart Internet Information Services (IIS) to correct this error.
- If you are upgrading an RMS cluster that is installed on a domain controller, you must add the Usługi AD RMS Service Group to the IIS_WPG group on the domain controller. Membership in the IIS_WPG group is required for running the Usługi AD RMS application pool (_DRMSAppPool1).
- If you deployed RMS on a domain controller and protected the RMS key by using a software- or hardware-based cryptographic storage provider instead of having RMS centrally manage the private key, you cannot upgrade the cluster to Usługi AD RMS on that domain controller. You must first join a Windows Server 2008-based member server to the RMS cluster to upgrade this cluster to an Usługi AD RMS cluster. We recommend that you remove RMS from the domain controller after the RMS cluster has been upgraded to Usługi AD RMS.
- An upgrade of an RMS cluster that is installed on a domain controller using an hardware-based CSP will not succeed because the Usługi AD RMS Service Group is created as a domain group on the domain controller and not as a local group. You must first join a Windows Server 2008-based member server to the RMS cluster to upgrade this cluster to an Usługi AD RMS cluster. We recommend that you remove RMS from the domain controller after the RMS cluster has been upgraded to Usługi AD RMS.
- If RMS is installed but not provisioned and you upgrade to Windows Server 2008, the upgrade link still appears in Server Manager. If you click this link and RMS was not provisioned, the upgrade fails.
Upgrade from Pre-Release AD RMS to AD RMS on Released Windows Server 2008 or Repair Upgrade of AD RMS on Released Windows Server 2008
The following list contains known issues when doing an in-place upgrade from Usługi AD RMS in a pre-release version of Windows Server 2008 to Usługi AD RMS in a released version of Windows Server 2008 or a repair upgrade of Usługi AD RMS.
- After doing an in-place upgrade, you can delete the PortNumber and SSLStatus registry entries, if they exist, from:
HKEY_LOCAL_MACHINE\Software\Microsoft\DRMS\2.0
However, Usługi AD RMS functionality is not affected if the settings are not deleted.
- After doing an in-place upgrade, you can remove the following folder, if it exists:
%windir%\system32\rms\performance.
However, functionality is not affected if the directory is not removed.
- The Active Directory Federation Services (AD FS) virtual directories are removed if you are upgrading from Windows Server 2008 with both Usługi AD RMS and AD FS installed. You must reinstall AD FS support after the Usługi AD RMS upgrade is complete.
- If you are using a port other than 80 to host your Usługi AD RMS cluster, the Usługi AD RMS Upgrade Wizard will bind two ports to this Web site during the upgrade. You must remove the incorrect binding and restart Internet Information Services before the Usługi AD RMS cluster can service requests.
- Custom access control lists (ACLs) that are applied to the Admin and GroupExpansion virtual directories are not migrated during the upgrade. If you have a custom ACL on either of these directories, you must set them up manually after the upgrade.
- If Usługi AD RMS was provisioned using a hardware security module (HSM), you must reinstall the HSM drivers after the repair upgrade of Windows Server 2008 is complete.