when Jim, Steve and I wrote up a good part of the certification
specification we added a functional requirement for "reauthentication".

This means that:

a) Ask a user for new authentication, if he is trying to do something
that he can not do, but might be possible if he provides a different log

b) Ask a user for new authentication, if he was logged in for N minutes.

I'm quite sure that part b) isn't written yet, but I'm not sure what the
state of part a) is.


