%% You should probably cite rfc8120 instead of this I-D. @techreport{ietf-httpauth-mutual-08, number = {draft-ietf-httpauth-mutual-08}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-httpauth-mutual/08/}, author = {Yutaka Oiwa and Hajime Watanabe and Hiromitsu Takagi and Kaoru Maeda and Tatsuya Hayashi and Yuichi Ioku}, title = {{Mutual Authentication Protocol for HTTP}}, pagetotal = 54, year = 2016, month = jul, day = 7, abstract = {This document specifies a mutual authentication scheme for the Hypertext Transfer Protocol (HTTP). This scheme provides true mutual authentication between an HTTP client and an HTTP server using password-based authentication. Unlike the Basic and Digest authentication schemes, the Mutual authentication scheme specified in this document assures the user that the server truly knows the user's encrypted password.}, }