I\'m trying to protect a resource in tomcat so that only \"valid users\" (those with a valid login and password in the realm) can access it. They do not necessarily belong to a
Besides the auth-constraint you are adding to the security-constraint:
*
you need specify the security role in the web-app: