Frank has two interesting blog entries that relate to security
The first is entitled http://www.orablogs.com/fnimphius/archives/000663.html - (broken link) ADF JClient: JAAS authentication using ADF Business Components. This entry is talking about the fact that Frank is in the process of writing a paper about JAAS authentication and authorization ADF Business Components. He has given a preview here about the authentication part of this paper. This is an excellent preview and worth reading.
The second entry in Franks weblog is entitled http://www.orablogs.com/fnimphius/archives/000662.html - (broken link) ADF JClient: How to create a signed ADF Client ear file for Java web start deployment with external keystore. This is again an excellent short article covering the issue of how to use an external keystore when using a self sign certificate to sign the ADF JClient libraries when creating an EAR file. Frank goes through the details of how to modify the build files to achieve this goal. Again this is an excellent short article well worth reading.