You are correct. GlassFish will not generate the WWW-Authenticate for the error page.
I have not used openSSO for a while. In the past, the openSSO will redirect the user to login page.
It is not correct to use the error page to authenticate users.
[Message sent by forum member 'swchan2']
http://forums.java.net/jive/thread.jspa?messageID=469463