Arizona State University Information Technology: WebAuth IT Home Ask IT WebAuth Home IT Search Arizona State University

WebAuth Policies and Server Registration


WebAuth and ASU Computing Policies

In order for an application to use WebAuth, the application server must first be registered with Information Technology. Providers take responsibility as the first point of network vulnerability and inform themselves about all precautions and protections that are necessary. In particular, WebAuth enabled application developers must adhere to University policies and WebAuth standards and implementation practices listed below:

  • Providers must register their single sign-on service with Information Technology using this WebAuth V2.0 Registration site.
  • Providers must deploy their web application via secure-http (https).
  • Providers must use a form "POST" to weblogin.asu.edu for user authentication. Form data must not pass through any other servers.
  • Single sign-off will be provided by the application to destroy the authentication credential.
  • Providers must comply with the ASU Graphic Standards Manual available from the Web Advisory Group (WAG).
    • Attempts to misrepresent an officially endorsed authentication site or it's components including icons, logos, or reverse engineering an official authentication mechanism for the purpose of creating an otherwise unofficial authentication service is strictly forbidden.
    • The generic ASURITE login page is an excellent option for most service providers. You can view the current version of the page at https://weblogin.asu.edu/cgi-bin/login. It has a look and feel that is similar to the myASU login page, and is also similar to the centrally maintained credit card information page. This familiarity gives the customer a visual reassurance that they are in a secure environment. It also provides for a clear threshold of copyright violation if any parties outside ASU choose to emulate the sign-on page.
  • Providers must adhere to ASU University policies. For related information about computer and electronic communications, see the Academic Affairs Manual-ACD 125, "Computer, Internet, and Electronic Communications".
    • Passwords may not be requested by means other than ASU officially endorsed authentication mechanisms.
    • User identification may not be used except for the official purpose of authentication and authorization.

WebAuth best practices are outlined in the WebAuth v2.0 Authentication service documentation. The document details the methods for a safe and secure WebAuth implementation.

Register an Application Server for use with WebAuth

As a sponsor of the WebAuth enabled application, you will need to provide the following information before your application can be registered:

Name:
Your E-mail Address:
Your ASURITE UserID:
Co-sponsor Name:
Co-sponsor E-Mail Address:
Co-sponsor ASURITE UserID:
Identify Your Server:
callapp=https://[]
Specify registration type:
Add Revoke Renew
Additional information regarding this registration:

By selecting "Submit/Accept", you are agreeing to the terms and conditions of the WebAuth standards and practices statements above. Please retain a copy of your registration for your records.


You will receive confirmation of registration within 24 hours if received during regular working hours.

Please, be sure to read the WebAuth v2.0 Authentication service documentation before you attempt to implement WebAuth. This implementation documentation outlines mechanisms for a safe and secure implementation and is strictly enforced.