How to protect our Tomcat site with CAC cards
We would like to protect our Tomcat server using DoD CAC cards, but cannot decide how this should be done.
Should we install a Sun ONE Identity Server or is there a way to configure Tomcat to authenticate clients directly from the CAC card reader software? I
t is certainly easy enough to turn on client auth in the connector in the server.xml, but this does not seem to be enough to authenticate against CAC cards...

