I'm interested in your comments about the subdomain. I'm looking at using them too but I don't have quite the same requirements.
You will need cookies if you want automatic login, where a browser is closed and sometime later a new one is opened.
I've mucked about with sessions but not used them extensively yet. However I've found that the sessions expire after a timeframe you specify, provided the browser is kept open.
I'll be interested to see how this thread progresses 🙂