Section 11.1 Basic Authentication Scheme The non-terminal "basic-cookie" may lead to incorrect associations or inferences with HTTP State Management, aka "cookies". I propose the replacement "enc-user-pass" or "base64-user-pass". Dave Kristol