Encrypt-then-HMAC is the only credible choice. Here's why
ietf.org
ietf.org
What's the problem with GCM?
It's just a specific MAC that has its security properties intended to work with the counter-mode encryption, and lets you use the same key, and basically gets the details right for you. But the motivation for it doing encrypt-then-authenticate instead of vice versa is presumably the same as with separate encryption and HMAC.