Can we get away with federating user and credentials only? Only store those in LDAP/AD? Would sure make our lives a lot easier and this may cover 80% of deployments that need it? -- Bill Burke JBoss, a division of Red Hat http://bill.burkecentral.com