Everytime asked yourself what to do in order to use a basic password pop up as authentication mechanism instead of a form based login (which uses the HTML logon page)? This is how your web.xml file has to look like. (In addition, do not forget to use security constraints on all HTTP methods in the web.xml, as also a security role.)
<realm-name>Put here the name, which appears as header in the basic password pop up</realm-name>
<display-name>Authenticated users only</display-name>
In addidion, add a security role mapping to your web-j2ee-engine.xml.