Session handling and SSL
| From: | Sam Leibowitz | Date: | Mon, 26 Mar 2001 22:12:27 +0000 |
| Subject: | Session handling and SSL | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-45656@lists.php.net to get a copy of this message | ||
Apologies if this has been addressed earlier.
I'm using session.auto_start under an apache-ssl driven site, and it seems
that the sesion ID cookies aren't being sent with the "secure" flag
set. As a result, the browser is effectively ignoring the cookie.
Is this an obvious configuration problem that I'm too dumb to figure out,
or should I actually be worried?
Thanks,
Sam Leibowitz (sleibowitz@btcwcu.org)
Project Manager
Business Technology Center (http://www.btcwcu.org)