The following entry by Rob Monzillo contains an extensive look at the use of Java Authentication Service Provider Interface for Containers -- JSR-196 -- directly applied to Glassfish, Sun's reference implementation for a Servlet container Read Rob's complete post on JSR-196 http://blogs.sun.com/enterprisetechtips/entry/adding_authentication_mechanisms_to_the