> I think it is worth investing some WG time into this proposal, because several proposals (+ existing Kerberos) are already multilegged. Otherwise new schemes would need to reinvent this, for example using "sid" directive.

I sought to generalize this with REST-GSS (which really uses SASL/GS2,
not GSS directly).  Any comments?


