Is there a way to mark classic ASP ASPSESSIONID* cookies as secure? It appears that the ASP ISAPI handler adds that session id cookie after my page is done rendering so put
[Edit: You can ignore the following. I just realized that you were talking about ASPSESSIONID.}
There is built-in support for secure cookies.
See http://msdn.microsoft.com/en-us/library/ms524757.aspx
Example (for ASP.Net, not Classic ASP):
Response.Cookies("setSecure") = "someValue"
Response.Cookies("setSecure").Secure = true