To implement authentication and authorization, new one has come up..JAAS - Java Authentication and Authorization Service..Hope it's comingwith tomcat..For more information see java.sun.com