the rules you should follow is like configuring using a database for authentication like for any other webapp. So try that first. View the original post : http://www.jboss.org/index.html?module=bb&op=viewtopic&p=4243050#4243050 Reply to the post : http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&p=4243050