This is nothing less than security by obscurity. 1. The cookies set by ISA will not work outside of the TCP and HTTP sessions. 2. There is no ASPSessionState or anything else of value to anyone who may try to persist these cookies elsewhere Therefore, there is no gain to trying to obfuscate these cookies. Whomever is making these suggestions is regurgistating; not thinking. Jim -----Original Message----- From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Jason Jones Sent: Wednesday, November 14, 2007 3:46 PM To: isapros@xxxxxxxxxxxxx Subject: [isapros] ISA Cookie Encryption? Is this possible to solve? http://forums.isaserver.org/m_2002057159/mpage_1/key_/tm.htm#2002057159 ________________________________ This email and any files transmitted with it are confidential and intended solely for the use of the individual to whom it is addressed. If you have received this email in error, or if you believe this email is unsolicited and wish to be removed from any future mailings, please contact our Support Desk immediately on 01202 360360 or email helpdesk@xxxxxxxxxxxxxxxxx If this email contains a quotation then unless otherwise stated it is valid for 7 days and offered subject to Silversands Professional Services Terms and Conditions, a copy of which is available on request. Any pricing information, design information or information concerning specific Silversands' staff contained in this email is considered confidential or of commercial interest and exempt from the Freedom of Information Act 2000. Any view or opinions presented are solely those of the author and do not necessarily represent those of Silversands Silversands Limited, 3 Albany Park, Cabot Lane, Poole, BH17 7BX. Company Registration Number : 2141393.