This sounds like you're not creatign a LTPA Token (which is a cookie shared by all the WebSphere applications). I think (but don't have the references at hand to check) that you do this by selecting LTPA instead of SWAM as your authentication method. This requires you, however, to use LDAP, a Windows Domain, or a custom registry intead of Local OS authentication. Check the WebSphere v5
security handbook redbook to be sure.
Kyle