If you put the security constraint in default-web.xml or web.xml in the war and "redeploy" the application, then it will work for the given web application.
There is an issue for the docroot. We are investigating this now.
[Message sent by forum member 'swchan2']
http://forums.java.net/jive/thread.jspa?messageID=475589