PicketBox is a Security Framework that provides Authentication, Authorization, Audit and Mapping capabilities for Java Applications. NOTE: If you are interested in federated identity management - then look at Project PicketLink (http://jboss.org/picketlink)