the request
door (the endpoint's path), supported (the mechanism OIDs),
wantMic, mutualOff, via, and record (false when the caller records
the authentication itself)
a promise of the verdict: code (one of OUTCOMES), ok,
status, wwwAuthenticate, reason, checks and the outcome's facts
Runs the whole SPNEGO exchange, from the Authorization header to a verdict; it writes nothing to the response.