#%PAM-1.0

auth       required                    pam_shells.so
auth       requisite                   pam_nologin.so
auth       required                    pam_faillock.so      preauth
# Optionally use requisite above if you do not want to prompt for the smartcard
# on locked accounts.
auth       [success=1 default=ignore]  pam_pkcs11.so        wait_for_card card_only
auth       [default=die]               pam_faillock.so      authfail
auth       optional                    pam_permit.so
auth       required                    pam_env.so
auth       required                    pam_faillock.so      authsucc
# If you drop the above call to pam_faillock.so the lock will be done also
# on non-consecutive authentication failures.
auth       [success=ok default=1]      pam_gdm.so
auth       optional                    pam_gnome_keyring.so

account    include                     system-local-login

password   required                    pam_deny.so

session    include                     system-local-login
session    optional                    pam_gnome_keyring.so auto_start
