#%PAM-1.0 auth required pam_securetty.so auth required pam_tally.so file=/var/log/faillog onerr=succeed no_magic_root auth required pam_shells.so auth required pam_nologin.so auth include system-auth account required pam_access.so account include system-auth account required pam_tally.so deny=0 file=/var/log/faillog onerr=succeed no_magic_root password include system-auth @selinux@# pam_selinux.so close should be the first session rule @selinux@session required pam_selinux.so close @selinux@ session required pam_env.so session optional pam_lastlog.so session optional pam_motd.so motd=/etc/motd session optional pam_mail.so # If you want to enable pam_console, uncomment the following line # and read carefully README.pam_console in /usr/share/doc/pam* #session optional pam_console.so session include system-auth @selinux@# pam_selinux.so open should be the last session rule @selinux@session required pam_selinux.so multiple open @selinux@