This looks quite good I would say.
Only thing to change: jboss-web.xml references a quite old DTD. Change it to:
{code:xml}
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE jboss-web PUBLIC "-//JBoss//DTD Web Application 2.4//EN" "http://www.jboss.org/j2ee/dtd/jboss-web_4_0.dtd">
{code}
For further diagnostics, activate logging of the security layer: http://community.jboss.org/wiki/SecurityFAQ - question 4.
Best regards
Wolfgang