%% You should probably cite draft-williams-rest-gss-02 instead of this revision. @techreport{williams-rest-gss-01, number = {draft-williams-rest-gss-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-williams-rest-gss/01/}, author = {Nicolás Williams}, title = {{RESTful Hypertext Transfer Protocol Application-Layer Authentication Using Generic Security Services}}, pagetotal = 23, year = 2012, month = jun, day = 2, abstract = {This document describes a method for application-layer authentication in Hypertext Transfer Protocol (HTTP) applications using Generic Security Services Application Programming Interface (GSS-API) mechanisms via, for simplicity, the Simple Authentication and Security Layers (SASL) mechanism bridge known as "GS2". This approach to authentication allows for pluggability, mutual authentication, and channel binding, all with no changes to HTTP nor the Transport Layer Security (TLS). We hope that the use of mutual authentication and channel binding at the application layer will make phishing more difficult. We hope that the use of authentication at the application layer will make REST-GSS deployable.}, }