[Catalyst] Making secure session cookies (or, how do we make Explorer stop complaining about nonsecure content on a secure page?)

Not sure if someone's suggested this so far, but perhaps one of the resources you're including using https: is getting a redirect back to a non-SSL URL?
