Nikolaj at Digital Identity mentions Consult Hyperion's whitepaper on identity management. Big points to him for also posting a link in the same article to Carl Ellison and Bruce Schneiers classic: What You're not Being Told about Public Key Infrastructure. Nice one.
All enterprise java developers should have at least a passing knowledge of JCE. If you've never tried it before try this quick little intro to sample it: Master the basics of Java Cryptography Extension (JCE). [builder.com]