Hm, ripping kerberos from libssl I can understand -- but from base? Does that mean that openssh certificate is what people are using for federated authentication? While kerberos <i>is</i> complex and complected -- are there any solutions that are better, if you require administrating a non-trivial number of users, along with a good way to immediatly revoke access as users leave the organization?