>
>
>
> No. That is by design. The session ID is almost as valuable as the
> password. If you need SSL to protect the password, you should use SSL to
> protect the session ID.
>
>
Well, that's fairly application specific, but the argument has also been
done to death elsewhere.  Workaround is already in place.

Reply via email to