Was just about the start working on a new security-policy file to layout the default handler chains for inbound message evaluation when I realized the directory's getting a little crowded. Should we carve things up inside conf/ or leave everything at that level? Authentication config files in particular are probably the largest set. -- Scott