The issue of establishingidentity, positively and absolutely, is one that continues to be intensely discussed and debated.
The best SSL can do on this front is to require client certificates as proof of identity when establishing the connection between the client and server.
This is borne out by my notes from a meeting with Woody, during which he said: "we will gain more than we will lose by establishing an identity; my tendency would be to risk being more offensive."