posted 22 years ago
The certificate is for the entire (SSL/TLS) session. This session is defined at the secure socket layer and is quite different from the HTTP session you may be familiar with[1]. I'm not entirely sure at what point your typical browser ends that session -- when you go off to another site, I'd guess.
Does this help or does it look like mumbo-jumbo to you?
- Peter
[1] Having said that, an application server will typically use the SSL/TLS session rather than cookies to manage its HTTP session if accessed via secure HTTP.
[ May 12, 2003: Message edited by: Peter den Haan ]
Peter den Haan | peterdenhaan.com | quantum computing specialist, Objectivity Ltd