Isn't this what the GSS-API is about? Couldn't HTTP-NG just convey GSS "tokens", and do something about getting both sides to agree on which GSS "mechanism" is to be used, and on what Principals are involved?