It seems that the answer to this question would be obvious provided that HTTP sessions and EJBs are cluster aware, but I'd ask just in case.
Is JAAS cluster aware. In other words does a security context span multiple EJBs and servlets across multiple VMs?