Our SSL appliance seems to be stripping the HTTPOnly flag from the cookie sent from the server. I see it on the unencrypted side but then the flag is...