RE: proxy authentication

> Any mechanism with man-in-the-middle protection... e.g. DIGEST-MD5.

No part of the DIGEST-MD5 exchange is dependent on the individual machines
in the transaction. As such, DIGEST-MD5 has no man-in-the-middle protection.
Also see http://www.ietf.org/rfc/rfc2831.txt section 3.6 which states

   Digest authentication is vulnerable to "man in the middle" (MITM)

The only way to defend against this is to secure the channel between the
authenticating server and the proxy.

