Okay, so I\'ve been running a Java/Jersey webservice on Tomcat with basic authentication which works perfectly fine. I\'ve got permissions set up in the web.xml file of my proje
After writing all this below I remember I have blogged about this for myself here:
WebSphere 6.1 and Application Authentication
As I understand you have setup your web.xml correctly thus:
     
    myrole 
   
  
    
      mySec 
      /yourUrl 
      DELETE 
      GET 
      POST 
      PUT 
      HEAD 
      TRACE 
      OPTIONS 
     
    
      myrole 
     
    
      SSL or MSSL not required 
      NONE 
     
   
  
    BASIC 
    my login 
   
This is if you are using the administration console you dont state that you are not so go to the console:
http://localhost:9060/ibm/console
Then login (if you have administrative security setup)
Then go here
Then you have application security turned on. Now you need to map the users of your application to users within websphere.
Go here
Administration security (security of Websphere itself) must be turned on for it to work.
WebSphere can be complex but it is powerful and capable.