We had a recent security audit, and we're advised to set the "secure" and "httponly" flag for all cookies. We're running IIS 7.5.
Can anyone tell me how to do this and/or point me to a resource they like that could help me get this done?
Thank you!
Ed