Hi again, I checked with my webhost and this is his reply...a bit out of my depth...is this not a problem for lots of Zencart installations?
Cookies are generally associated with a domain. Because the secure server is not in the same domain as the main website, a technique must be employed to ensure that the session id is moved between the two. In some cases this can be done by appending it to the URL, I know of one instance where the user has kept it in a hidden field on their form and then picks up the session stuff in their script.
It is possible to pass session stuff between our secure server and your website, we have people doing so. You may need to experiment with how best to do so. Unfortunately, because all the sites we host are 'virtual', we can not provide a secure service using your own domain.
This is usually accomplished using multiple IP numbers and we are unable to provide a site with its own IP number.
Bookmarks