> What is do the authors mean by "implicit server authentication" ? > How does this reflect on the behavior of the server and the client ? I believe this is a hedge to allow for protocols like Kerberos or meta-protocols like GSSAPI to be involved in the key exchange stage. - Bill