fd7089e
#%PAM-1.0
a5988fe
auth       substack     system-auth
a5988fe
auth       include      postlogin
fd7089e
account    required     pam_nologin.so
fd7089e
account    include      system-auth
fd7089e
password   include      system-auth
fd7089e
# pam_selinux.so close should be the first session rule
fd7089e
session    required     pam_selinux.so close
fd7089e
session    required     pam_loginuid.so
fd7089e
# pam_selinux.so open should only be followed by sessions to be executed in the user context
fd7089e
session    required     pam_selinux.so open
fd7089e
session    required     pam_namespace.so
fd7089e
session    optional     pam_keyinit.so force revoke
fd7089e
session    include      system-auth
a5988fe
session    include      postlogin
fd7089e
-session   optional     pam_ck_connector.so