i need some help on this plz.........Its about Security roles
i know why <principal-name> tag is used in descriptor( sun-web.xml ) files
its for binding a individual user to a security role
but i am not very clear about "class-name" attribute
i know that its optional . if we dont specify in descriptor( sun-web.xml ) files it will take a default class "com.sun.enterprise.deployment.PrincipalImpl"