Roger Harrison writes: > The AuthMeth draft already has the following security consideration: > > "Servers are encouraged to prevent modifications by anonymous users. " > > Perhaps that is sufficient. Yes, with a non-MUST, that sounds good enough. -- Hallvard