The following feature requests are open (not decided if they will be implemented yet)
- Using of SSL-ID in combination with MOD_BUT_SESSION
- Logout handler (for backend session destroy mechanism)
- Role-based authentication
- Support for client certificates
More details can be found in the following PDF: 