diff --git a/bakery.module b/bakery.module
index 606e9df..95e725a 100644
--- a/bakery.module
+++ b/bakery.module
@@ -72,7 +72,7 @@ function bakery_menu() {
       'access arguments' => array('administer users'),
       'page callback' => 'drupal_get_form',
       'page arguments' => array('bakery_pull_form'),
-      'type' => MENU_NORMAL_ITEM,     
+      'type' => MENU_NORMAL_ITEM,
     );
   }
 
@@ -793,6 +793,27 @@ function bakery_user_page() {
 }
 
 /**
+* Generate the name for a bakery cookie, this prevents domain
+* mismatch on subdomains that are not part of a parent domains bakery config.
+*
+* @param string $type
+*   CHOCOLATECHIP or OATMEAL, default CHOCOLATECHIP
+* @return string
+*   The namespaced cookie name for this environment.
+*/
+function _bakery_cookie_name($type = 'CHOCOLATECHIP') {
+  // Use different names for HTTPS and HTTP to prevent a cookie collision.
+  if (ini_get('session.cookie_secure')) {
+    $type .= 'SSL';
+  }
+  // Namespace the cookie by the cookie domain.  Use md5 to avoid using any
+  // reserved cookie terms (all of which contain non-hex characters):
+  //   "expires", "domain", "path", and "secure".
+  $name = $type . md5(variable_get('bakery_domain', ''));
+  return $name;
+}
+
+/**
  * Function to validate cookies
  *
  * @param $type (string) CHOCOLATECHIP or OATMEAL, default CHOCOLATECHIP
@@ -802,10 +823,7 @@ function bakery_user_page() {
 function _bakery_validate_cookie($type = 'CHOCOLATECHIP') {
   $key = variable_get('bakery_key', '');
 
-  $cookie_secure = ini_get('session.cookie_secure');
-  if ($cookie_secure) {
-    $type .= 'SSL';
-  }
+  $type = _bakery_cookie_name($type);
 
   if (!isset($_COOKIE[$type]) || !$key || !variable_get('bakery_domain', '')) {
     return;
@@ -1033,12 +1051,7 @@ function _bakery_bake_chocolatechip_cookie($name, $mail, $init) {
     $cookie['calories'] = 480;
     $cookie['timestamp'] = $_SERVER['REQUEST_TIME'];
     $cookie['signature'] = hash_hmac('sha256', $cookie['name'] . '/' . $cookie['mail'] . '/' . $cookie['timestamp'], $key);
-    // Use different names for HTTP and HTTPS to prevent a cookie collision.
-    $cookie_secure = ini_get('session.cookie_secure');
-    $type = 'CHOCOLATECHIP';
-    if ($cookie_secure) {
-      $type .= 'SSL';
-    }
+    $type = _bakery_cookie_name('CHOCOLATECHIP');
     setcookie($type, bakery_mix(serialize($cookie), 1), $_SERVER['REQUEST_TIME'] + variable_get('bakery_freshness', '3600'), '/', variable_get('bakery_domain', ''), (empty($cookie_secure) ? FALSE : TRUE));
   }
 }
@@ -1046,10 +1059,7 @@ function _bakery_bake_chocolatechip_cookie($name, $mail, $init) {
 function bakery_taste_oatmeal_cookie() {
   $key = variable_get('bakery_key', '');
 
-  $type = 'OATMEAL';
-  if (ini_get('session.cookie_secure')) {
-    $type .= 'SSL';
-  }
+  $type = _bakery_cookie_name('OATMEAL');
 
   if (!isset($_COOKIE[$type]) || !$key || !variable_get('bakery_domain', '')) {
     return;
@@ -1089,12 +1099,7 @@ function bakery_bake_oatmeal_cookie($name, $data) {
       $cookie['slave'] = $base_url . '/'; // Match the way slaves are set in Bakery settings, with ending slash.
     }
     $cookie['signature'] = hash_hmac('sha256', $name . '/' . $cookie['timestamp'], $key);
-    // Use different names for HTTP and HTTPS to prevent a cookie collision.
-    $cookie_secure = ini_get('session.cookie_secure');
-    $type = 'OATMEAL';
-    if ($cookie_secure) {
-      $type .= 'SSL';
-    }
+    $type = _bakery_cookie_name('OATMEAL');
     setcookie($type, bakery_mix(serialize($cookie), 1), $_SERVER['REQUEST_TIME'] + variable_get('bakery_freshness', '3600'), '/', variable_get('bakery_domain', ''), (empty($cookie_secure) ? FALSE : TRUE));
   }
 }
@@ -1364,10 +1369,7 @@ function bakery_eat_gingerbread_cookie() {
  * Destroy unwanted cookies
  */
 function _bakery_eat_cookie($type = 'CHOCOLATECHIP') {
-  $cookie_secure = ini_get('session.cookie_secure');
-  if ($cookie_secure) {
-    $type .= 'SSL';
-  }
+  $type = _bakery_cookie_name($type);
   setcookie($type, '', $_SERVER['REQUEST_TIME'] - 3600, '/', '', (empty($cookie_secure) ? FALSE : TRUE));
   setcookie($type, '', $_SERVER['REQUEST_TIME'] - 3600, '/', variable_get('bakery_domain', ''), (empty($cookie_secure) ? FALSE : TRUE));
 }
