Hi, all I found that JndiLoginModule will associate a UnixPrincipal, UnixNumericUserPrincipal, and the relevant UnixNumericGroupPrincipals with the subject if logging succeeds no matter whether it is a windows client or unix client. So I will move UnixPrincipal related classes from current Unix specified directory to common directory if no one objects. Good luck! Leo -- Leo Li China Software Development Lab, IBM