#%PAM-1.0 auth required pam_sepermit.so #auth substack password-auth auth required pam_krb5.so auth include postlogin # Used with polkit to reauthorize users in remote sessions -auth optional pam_reauthorize.so prepare account required pam_nologin.so account sufficient pam_krb5.so password sufficient pam_krb5.so # pam_selinux.so close should be the first session rule session required pam_selinux.so close session required pam_loginuid.so # pam_selinux.so open should only be followed by sessions to be executed in the user context session required pam_selinux.so open env_params session optional pam_keyinit.so force revoke session optional pam_krb5.so session include postlogin # Used with polkit to reauthorize users in remote sessions -session optional pam_reauthorize.so prepare