The old property-file based security manager shouldn't be used anymore. Instead use the JAAS InVMLoginModule for in-vm tests, embedded use-cases, etc. and use the other JAAS login modules for normal server use-cases.
Using the regular maven plugin framework, and adding the interceptors to the regular broker.xml configuration