Best way is to not send credentials in plain text. I wish SRP had taken off and become standard.
And by plain-text, I mean the server receives information that could then be used to authenticate later.
For instance, if you send the sha of a password, and then store the sha of the sha, you're still sending the password in plaintext, it's just that it's not the password the user entered.
This method is no less secure than the standard "client sends server password over HTTPS" scheme.
... and how do you set up a secure connection without a pre-existing password?
Your solution has a chicken-and-egg problem.
SRP does.
[0] http://en.wikipedia.org/wiki/Secure_Remote_Password_protocol
[0] http://en.wikipedia.org/wiki/Secure_Remote_Password_protocol