maybe we dont have to re-invent the wheel here: http://www.psynch.com/about/integration-auth.html P-Synch: Open architecture for authentication http://nareau.weblogs.com/ The Nareau Project(Identity Management) http://eugene.manilasites.com/stories/storyReader$127 Distributed single sign-on (SSO) system http://www.cni.org/projects/authentication/authentication-wp.html A White Paper on Authentication and Access Management Issues in Cross-organizational Use of Networked Information Resources http://java.sun.com/security/jaas/doc/acsac.html User Authentication and Authorization in the Java(TM) Platform http://www.dlib.org/dlib/june98/scout/06roszkowski.html A Distributed Architecture for Resource Discovery Using Metadata