<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DoD CAC and Apache</title>
	<atom:link href="http://www.mattpallotta.com/home/2009/05/07/dod-cac-and-apache/feed" rel="self" type="application/rss+xml" />
	<link>http://www.mattpallotta.com/home/2009/05/07/dod-cac-and-apache</link>
	<description>Yea, it is Me.</description>
	<lastBuildDate>Tue, 02 Mar 2010 17:39:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: matt</title>
		<link>http://www.mattpallotta.com/home/2009/05/07/dod-cac-and-apache/comment-page-1#comment-4</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Tue, 02 Mar 2010 17:39:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattpallotta.com/home/?p=231#comment-4</guid>
		<description>I am working on a new post with CRL&#039;s. This handles making sure only valid certs are allowed in. Then it is up the applications to handle the authorization.  One option is use opensso, there are a few sun.com blogs I have found talking about it.

The trick is merging the SSL_CLIENT_S_DN_CN(unique to everyone) in a friendly name. For me this would have to be across applications if there isn&#039;t an identity server running for everyone. Backend services can be written to supply common data at application registration.

Either way you would have to reach back to an Enterprise service to get &quot;Official&quot; information.</description>
		<content:encoded><![CDATA[<p>I am working on a new post with CRL&#8217;s. This handles making sure only valid certs are allowed in. Then it is up the applications to handle the authorization.  One option is use opensso, there are a few sun.com blogs I have found talking about it.</p>
<p>The trick is merging the SSL_CLIENT_S_DN_CN(unique to everyone) in a friendly name. For me this would have to be across applications if there isn&#8217;t an identity server running for everyone. Backend services can be written to supply common data at application registration.</p>
<p>Either way you would have to reach back to an Enterprise service to get &#8220;Official&#8221; information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario</title>
		<link>http://www.mattpallotta.com/home/2009/05/07/dod-cac-and-apache/comment-page-1#comment-3</link>
		<dc:creator>Mario</dc:creator>
		<pubDate>Tue, 23 Feb 2010 16:01:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattpallotta.com/home/?p=231#comment-3</guid>
		<description>Hi Have you figured out how to do user authentication with the above configuration?</description>
		<content:encoded><![CDATA[<p>Hi Have you figured out how to do user authentication with the above configuration?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
