*login()* gets called once, *authenticate()* many times. This seems to me to perfectly acceptable behaviour. View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4101280#4101280 Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4101280