87ca29
#%PAM-1.0
87ca29
auth       substack     password-auth
87ca29
auth       include      postlogin
87ca29
account    required     pam_nologin.so
87ca29
account    include      password-auth
87ca29
password   include      password-auth
87ca29
# pam_selinux.so close should be the first session rule
87ca29
session    required     pam_selinux.so close
87ca29
session    required     pam_loginuid.so
87ca29
# pam_selinux.so open should only be followed by sessions to be executed in the user context
87ca29
session    required     pam_selinux.so open
87ca29
session    required     pam_namespace.so
87ca29
session    optional     pam_keyinit.so force revoke
87ca29
session    include      password-auth
87ca29
session    include      postlogin