Pluggable authentication for OACS: moving towards a concrete plan

One point of clarification.  These APIs would most definitely NOT replace "ad_conn user_id".  The last thing we want is to have to modify every single tcl file in the system.  They would be consumed mostly by the pages under packages/acs-subsite/register/.