[Seaside-dev] tracking sessions by ssl session id?

Philippe Marschall philippe.marschall at gmail.com
Sun Aug 8 20:42:55 UTC 2010


Hi

Having the session id in the URL is a problem in some cases so I was
wondering whether it would be possible to use the SSL session id as an
alternative to cookies. Before starting any work:
- Are there any reasons why this is a terrible idea?
- Is there a way to get the SSL session id over mod_proxy?
- Which server adapters besides AJP support getting the SSL session
id? SqueakSSL/WebClient? SCGI? FastCGI? Swazoo? OpenTalk?

Cheers
Philippe


More information about the seaside-dev mailing list