authentication and encription is supposed to be provided by the underlying layer, HTTP. MS uses SSL for encription and NT proprietary crap for authentication, HTTP's own being to weak.