A method for single-sign on of a user on a client machine to one or more
target applications on target application servers in a computer
information-processing network, including: accessing an access server
from the client machine; entering user-specific access server logon
credentials for logon and access to the access server; selecting a target
application; presenting to the target application by the access server,
previously stored user-specific target application logon credentials for
logon and access to the target application in a form and according to a
protocol recognizable by the target application thereby logging into the
target application on behalf of the user and establishing a target
application session; sending from the access server to the client
machine, information for establishing a connection from the client
machine to the target application; and establishing a target application
session, bypassing the access server, between the client machine and the
target application.