Apologies if this has been addressed earlier. I'm using session.auto_start under an apache-ssl driven site, and it seems that the sesion ID cookies aren't being sent with the "secure" flag set. As a result, the browser is effectively ignoring the cookie. Is this an obvious configuration problem that I'm too dumb to figure out, or should I actually be worried? Thanks, Sam Leibowitz ([EMAIL PROTECTED]) Project Manager Business Technology Center (http://www.btcwcu.org) -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] To contact the list administrators, e-mail: [EMAIL PROTECTED]

