REST and HTTP Digest Authentication
It seems so simple: use the HTTP Digest Authorization with the Quality of Protection set to "auth".
It's an easy algorithm. A nonce that encodes a timestamp can be used to be sure no one is attempting to cache credentials. It's potentially very, very nice.
Except for one thing: Apache …
more ...