    authentication and authorization can be developed in servlet and xml. which one is best & flexible?

    There are different mechansims of handling security... to be honest, your question is not quite clear.. attached is the link for you to explore different security mechanisms.. http://java.sun.com/javaee/5/docs/tutorial/doc/Security-Intro.html#wp562908 Bhagvan K http://www.jroller.com/page/bhagvank