9d84b2
#%PAM-1.0
9d84b2
auth [user_unknown=ignore success=ok ignore=ignore default=bad] pam_securetty.so
9d84b2
auth       substack     system-auth
9d84b2
auth       include      postlogin
9d84b2
account    required     pam_nologin.so
9d84b2
account    include      system-auth
9d84b2
password   include      system-auth
9d84b2
# pam_selinux.so close should be the first session rule
9d84b2
session    required     pam_selinux.so close
9d84b2
session    required     pam_loginuid.so
9d84b2
session    optional     pam_console.so
9d84b2
# pam_selinux.so open should only be followed by sessions to be executed in the user context
9d84b2
session    required     pam_selinux.so open
9d84b2
session    required     pam_namespace.so
9d84b2
session    optional     pam_keyinit.so force revoke
9d84b2
session    include      system-auth
9d84b2
session    include      postlogin
9d84b2
-session   optional     pam_ck_connector.so