...Yes. RFC 2865 mentions only User-Password and CHAP-Password, and
refers to other "authentication information". We could extend the list
to include currently known authentication attributes. But I think it's
better to give directions for future efforts.Speaking of which, shouldn't this be in the design guidelines, rather than issues & fixes?