Securing Session ID: ASP/ASP.NET
Checking through the Kb article ( http://support.microsoft.com/kb/274149 ) “IIS supports the use of a Session ID cookie to track the current session identifier for a web session. However, .ASP in IIS does not support the creation of secure Session ID cookies as defined in RFC 2109.

Go here to see the original:
Securing Session ID: ASP/ASP.NET


