%% You should probably cite rfc8120 instead of this I-D. @techreport{ietf-httpauth-mutual-02, number = {draft-ietf-httpauth-mutual-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-httpauth-mutual/02/}, author = {Yutaka Oiwa and Hajime Watanabe and Hiromitsu Takagi and Kaoru Maeda and Tatsuya Hayashi and Yuichi Ioku}, title = {{Mutual Authentication Protocol for HTTP}}, pagetotal = 52, year = 2014, month = apr, day = 24, abstract = {This document specifies a mutual authentication method for the Hyper- text Transfer Protocol (HTTP). This method provides a true mutual authentication between an HTTP client and an HTTP server using password-based authentication. Unlike the Basic and Digest authentication methods, the Mutual authentication method specified in this document assures the user that the server truly knows the user's encrypted password.}, }