Just skip the plaintext password (the sequence of ports transmitted) and use certificate based auth, as you note below.