>It's hard for me to imagine an auth-scheme that can work correctly >and usefully with zero auth-param's in the credentials. It is for an auth-scheme that sends its parameters in separate header field(s) rather than as auth-param's. ....Roy