account		required	pam_nologin.so
account		include		system-auth
password	include		system-auth

# pam_selinux.so close should be the first session rule
session		required	pam_selinux.so close
session		required	pam_loginuid.so
#to require a local user account, uncomment this line:
#session		required	pam_localuser.so
session		sufficient	pam_systemd.so class=background type=x11

# pam_selinux.so open should only be followed by sessions to be executed in the user context
session		required	pam_selinux.so open
session		required	pam_namespace.so
session		optional	pam_keyinit.so force revoke
session		include		system-auth
session		include		postlogin
-session	optional	pam_ck_connector.so
