Eric Greenberg wrote:
>
> Correlating the IP address and session ID is a reasonable thing to do in my
> opinion.  If they do not match you should merely request that the client
> reauthenticate themselves at which point you can establish a new session ID.

How can a simple CGI-BIN obtain the SSL session ID from the web
server? Is there an env var for this?

Ciao, Michael.

Reply via email to