In our current system, we have some customized logic (i.e. set up
security questions and answers, read and agree on our security policy
etc.) during user authentication process (using novell SDK
authentication class extension). Now we added federation (external IDP)
so that our NAM trusts external IDP, allowing other users to use our
applications. We still want to have some of our logic plugged in to the
whole process after an external user get authenticated and before the
user is granted access to our apps. Since this is a trust and we
configured NAM to use external IDP, we cannot use our own authentication
class anymore, whats the best way of injecting these logics into the

