IlyaM,
Thanks for the encouraging news. I did some checking based on your input and found that the spoofing of REMOTE_USER has to do with some scripts relying on globals from CGI rather than looking directly at the ENV hash. I don't pretend to know the innards of what that means. I do know that I use the ENV variables directly and based on your comment and what I could find it appears to be solid.
Thanks
Claude