be5bab
#%PAM-1.0
be5bab
auth       substack     password-auth
be5bab
auth       include      postlogin
be5bab
account    required     pam_nologin.so
be5bab
account    include      password-auth
be5bab
password   include      password-auth
be5bab
# pam_selinux.so close should be the first session rule
be5bab
session    required     pam_selinux.so close
be5bab
session    required     pam_loginuid.so
be5bab
# pam_selinux.so open should only be followed by sessions to be executed in the user context
be5bab
session    required     pam_selinux.so open
be5bab
session    required     pam_namespace.so
be5bab
session    optional     pam_keyinit.so force revoke
be5bab
session    include      password-auth
be5bab
session    include      postlogin