Gienger, PascalWaldvogel, MarcelMüller, PaulNeumair, BernhardRodosek, Gabi Dreo2019-01-112019-01-112011978-3-88579-281-9https://dl.gi.de/handle/20.500.12116/18973Web-based interfaces to applications in all domains of university life are surging. Given the diverse demands in and the histories of universities, combined with the rapid IT industry developments, all attempts at a sole all-encompassing platform for single-sign-on (SSO) will remain futile. In this paper, we present an architecture for a meta-SSO, which is able to seamlessly integrate with a wide variety of existing local sign-in and SSO mechanisms. It is therefore an excellent candidate for a university-wide all-purpose SSO system. Among the highlights are: No passwords are ever stored on disk, neither in the browser nor in the gateway; its basics have been implemented in a simple, yet versatile Apache module; and it can help reducing the impact of security problems anywhere in the system. It could even form the basis for secure inter-university collaborations and mutual outsourcing.enPolybius: Secure web single-sign-on for legacy applicationsText/Conference Paper1617-5468