There is JBossNegotiation that does the kerberos stuff for the web layer. There is plan to do it for EJBs/ws etc. View the original post : http://www.jboss.org/index.html?module=bb&op=viewtopic&p=4216000#4216000 Reply to the post : http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&p=4216000