    Could anyone provide some guidelines on how to implement user authentication within orion server? (E.g. What has to be specified in the deployment descriptors etc.)

    Any URLs that might be useful in this respect would be most welcome.

  2. Orion user authentication

    You should first of all study orion API. Download docs from www.orionserver.com (if you haven't already done so). In the docs bundle you will find api directory, where Orion JavaDocs dwell.

    Orion has some interfaces and there implementations to implement user management and authentication. They are:
    (com.evermind.security.)RoleManager, UserManager, User, Group, etc. Orion's RoleManager, for example, can be retrieved with the following line:

    RoleManager manager = (RoleManager)new InitialContext().lookup("java:comp/RoleManager");

    With the role manager you can create/remove roles/principals, login users etc. (see docs).