This blog has been replaced by Securing your MVC Application