SSO between Windows Desktop Login and IdM

What do you think the easiest way would be to SSO a user from thier windows session to Identity Manager?
[111 byte] By [DeepEllumMatt] at [2007-11-26 10:54:10]
# 1
One way that I've seen it accomplished is through Sun Access Manager protecting the Identity Manager website and using the Kerberos authentication auth method to check and see if the AD user has an active AD session.
SavorToday at 2007-7-7 3:07:01 > top of Java-index,Web & Directory Servers,Directory Servers...
# 2
Another way is to issue each user a digital certificate into their certificate store and then roam that with their desktop. Then configure IDM to use certificate-based authentication.
ca_cudmore at 2007-7-7 3:07:01 > top of Java-index,Web & Directory Servers,Directory Servers...