Have you implemented simple APIs for principal and role propagation? Specifically so that we can bypass your security abstractions when they are not needed? -- Bill Burke JBoss, a division of Red Hat http://bill.burkecentral.com