This link provided me with a good understanding of what a P3P compact policy is all about http://www.oreillynet.com/pub/a/javascript/2002/10/04/p3p.html
To create the policy, somewhere in the article there is a link to IBMs free P3P policy creator. Download the program and create your P3P policy. (its a simple process)
There's also numerous online services to create the policy e.g. http://www.p3pwriter.com , but you have to pay
Then insert the "CP=....." part of the policy into the Web.xml file located located in the AwareIM/Tomcat/webapps/AwareIM/WEB-INF directory:
Example:
<context-param>
<param-name>cookie-policy</param-name>
<param-value>NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM</param-value>
</context-param>
B.T.W, you could use the the above example as your policy, but it will not reference your companies Private Policy. So it depends how you interpret the legalities of having a fake policy on your server.
You can test your http header by using the free utility at http://www.p3pwriter.com/LRN_122.asp.
Hope that makes sense