> I have hinted at mechanisms in which I believe the multi handshakes used by
> KERBEROS and GSSAPI  may be done within the existing http protocols.

Note that the GSSAPI is a different class of `thing' than Kerberos, and
is indeed very generic; a Web security context establishment
meta-protocol that mentioned only the GSSAPI, and avoided mention of any
specific security mechanism, could support a variety of actual security


