be5bab
#%PAM-1.0
be5bab
auth       substack     system-auth
be5bab
auth       include      postlogin
be5bab
account    required     pam_nologin.so
be5bab
account    include      system-auth
be5bab
password   include      system-auth
be5bab
# pam_selinux.so close should be the first session rule
be5bab
session    required     pam_selinux.so close
be5bab
session    required     pam_loginuid.so
be5bab
# pam_selinux.so open should only be followed by sessions to be executed in the user context
be5bab
session    required     pam_selinux.so open
be5bab
session    required     pam_namespace.so
be5bab
session    optional     pam_keyinit.so force revoke
be5bab
session    include      system-auth
be5bab
session    include      postlogin
be5bab
-session   optional     pam_ck_connector.so