From: <glassfish_at_javadesktop.org>
Date: Wed, 24 Oct 2007 09:14:52 PDT
the remote invocation of the ejb will occur over the RMI/IIOP protocol and your client side ORB must be capable of injecting the necessary security information in the outgoing protocol messages. I have included some references which describe how to configure your standalone client to use the glassfish ORB with its inherent ability to inject the CSIv2 security information.
if you have not done so already, please consult the sections regarding standalone clients in he following: