On Fri, Mar 21, 2008 at 12:47:05PM -0400, Sam Hartman wrote: > Is it? I'm not sure sub-negotiation would be valuable for this > mechanism even if we could make it work. As discussed earlier in the thread, since the server knows what verifiers it has for a given user, it would be useful for the hash negotiation to happen inside the mechanism.