%% You should probably cite draft-hallambaker-httpsession-03 instead of this revision. @techreport{hallambaker-httpsession-02, number = {draft-hallambaker-httpsession-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hallambaker-httpsession/02/}, author = {Phillip Hallam-Baker}, title = {{HTTP Session Management}}, pagetotal = 20, year = 2014, month = jan, day = 21, abstract = {The HTTP Session Management Mechanism provides a mean of securely establishing a persistent authentication session between a HTTP client and server that does not rely on the presentation of a confidential bearer token. The Session Management Mechanism is intended to provide a replacement for the existing HTTP State Management Mechanism (Cookies) for this purpose. This document defines the HTTP Accept-Session, Set-Session and Session headers and specifies their use to establish symmetric authentication keys and their use to authenticate and verify specific parts of an HTTP message. Other means by which keys used to authenticate the messages are established are outside the scope of this document.}, }