#%PAM-1.0

auth       required   pam_tally.so         onerr=succeed file=/var/log/faillog
auth       required   pam_shells.so
auth       requisite  pam_nologin.so
auth       include    system-auth

account    required   pam_tally2.so 
account    required   pam_access.so
account    required   pam_nologin.so
account    include    system-auth

password   include    system-auth

# pam_selinux.so close should be the first session rule
session    required   pam_selinux.so close
session    optional   pam_loginuid.so
session    include    system-auth
# pam_selinux.so open should only be followed by sessions to be executed in the user context
session    required   pam_selinux.so open
session    optional   pam_motd.so          motd=/etc/motd
session    optional   pam_mail.so          dir=/var/spool/mail standard quiet
-session   optional   pam_systemd.so
session    required   pam_env.so
