#%PAM-1.0
auth		required	pam_sepermit.so
auth		substack	common-login
auth		optional	pam_ssh_add.so
# List of users to deny access to Cockpit, by default root is included.
auth		required	pam_listfile.so item=user sense=deny file=/etc/cockpit/disallowed-users onerr=succeed
account		required	pam_nologin.so
account		include		common-login
password	include		common-login
# pam_selinux.so close should be the first session rule
session		required	pam_selinux.so close
session		required	pam_loginuid.so
# pam_selinux.so open should only be followed by sessions to be executed in the user context
session		required	pam_selinux.so open env_params
session		optional	pam_keyinit.so force revoke
session		optional	pam_ssh_add.so
session		optional	pam_motd.so
session		include		common-login
