Single sign-on has already reduced password fatigue considerably by letting users authenticate once and access many connected applications, but most SSO implementations still rely on a password at that initial authentication step, preserving the exact weakness SSO was meant to reduce. Certificate-based SSO removes that remaining password dependency entirely. This article covers how this works and what it takes to deploy well.