> But doesn't one-way authentication without mutual authentication imply > a different trust model? I.e one end chooses to not to authenticate > while the other end does authenticate. Yes, but the point was that the document already talks about this by explicitly separating the client side from the server side considerations. Erik