Bruce,
SSL is ultimately where we are headed. However, since we would not be revealing any state secrets should the userID/Password be intercepted, we decided to implement without the SSL. I concur, however, that logins should ALWAYS be SSL.
Thanks! I will make the change although I don't foresee anyone requesting the page via a POST procedure. However, I may decided to do so myself sometime so it will save another round of head-scratching...
Rob