mention NTLM as something that violates the stalessness requirement

     361       content: "Expires January 5, 2012";
     412      <meta name="dct.issued" scheme="ISO8601" content="2011-07-04">
     444               <td class="left">Expires: January 5, 2012</td>
     497               <td class="right">July 4, 2011</td>
     527      <p>This Internet-Draft will expire on January 5, 2012.</p>
    Recipients MUST consider every message in a connection in isolation; because HTTP is a stateless protocol, it cannot be assumed that two requests
    940          on the same connection are from the same client or share any other common attributes.
     940         on the same connection are from the same client or share any other common attributes. In particular, intermediaries might
     mix requests from different clients into a single server connection. Note that some existing HTTP extensions (e.g., [RFC4559]) violate this requirement, thereby potentially causing interoperability and security problems.
    13.2 Informative References
     2852      <table>                                                   
    29502951            <td class="top"><a href="mailto:tony+urireg@maillennium.att.com" title="AT&amp;T Laboratories">Hansen, T.</a>, <a href="mailto:hardie@qualcomm.com" title="Qualcomm, Inc.">Hardie, T.</a>, and <a href="mailto:LMM@acm.org" title="Adobe Systems">L. Masinter</a>, “<a href="http://tools.ietf.org/html/rfc4395">Guidelines and Registration Procedures for New URI Schemes</a>”, BCP&nbsp;115, RFC&nbsp;4395, February&nbsp;2006.
     [RFC4559]
     Jaganathan, K., Zhu, L., and J. Brezak, "SPNEGO-based Kerberos and NTLM HTTP Authentication in Microsoft Windows", RFC 4559, June 2006.
     RFC4559  2.2, 13.2
