Looking at RFC 2965... it seems that the comma's have to go... at least to be compatible with the future spec. Here is the snippet from the spec:
Note: For backward compatibility, the separator in the Cookie header
is semi-colon (;) everywhere. A server SHOULD also accept comma (,)
as the separator between cookie-values for future compatibility.
(closed it that time :)