In some multitiered applications, it is desirable for the user?s authenticated identity at one tier to be useable for requesting processing at the next tier. The current tier impersonates the user to the next tier to get work done securely under the identity of the user.
Some useful links :
http://www.brown.edu/Facilities/CIS/...ices/web-auth/
http://ask.slashdot.org/article.pl?sid=05/10/26/195250
http://www.oit.duke.edu/~rob/kerberos/authvauth.html