Security question

Hi Everyone,
Another dumb security question...
Our team have Tomcat 5.0.18 and Jboss3.2.3 running as Web-container and
app-container respectively. We want to use form based authentication on the
web-container and standard J2EE declarative security to allows authorized
access to EJBs.
Does anyone have any experience with this type of requirement? I'm looking
for a 'Aye' or specific words of caution.