I've blogged before on OpenSSO Extensions - useful modules that do not fit into the OpenSSO 'core'. Among the various categories of extension are 'authentication modules' - one of the most common customizations for OpenSSO and Access Manager . An authentication module supports a particular mechanism for collecting and verifying a user's credentials - common mechanisms that are supported out-of-the-box include username/password against LDAP, client certificates (encompassing browser certs and smartcards)
Read More...