<blockquote> How about sharing cookies between http and https for the same server?
</blockquote>
We *must* be able to share cookies between http and https for the same server. Otherwise if you have a mixed http and https site and require login over https, you will never be logged in (and can never get logged in) on the http side.