Approved client-server authentication mechanisms are described for the IVOA single-sign-on profile: No Authentication; HTTP Basic Authentication; TLS with passwords; TLS with client certificates; Cookies; Open Authentication; Security Assertion Markup Language; OpenID. Normative rules are given for the implementation of these mechanisms, mainly by reference to pre-existing standards. The Authorization mechanisms are out of the scope of this document.
@article{arxiv.1709.00171,
title = {IVOA Recommendation: SSO - Single-Sign-On Profile: Authentication Mechanisms Version 2.0},
author = {Giuliano Taffoni and André Schaaff and Guy Rixon and Brian Major},
journal= {arXiv preprint arXiv:1709.00171},
year = {2019}
}