If Client C calls EJB A, and EJB A calls EJB B, then will the methods in B be invoked with the same security context of Client C?

Prasad Thammineni

It depends on how you configure the EJBs. If you set the EJB A and B's run-as-modes to CLIENT_IDENITY in the deployment descriptor, all methods in A and methods in B will execute within the security context of Client C.