3 auth required pam_faillock.so preauth
4 # Optionally use requisite above if you do not want to prompt for the password
6 auth [success=2 default=ignore] pam_unix.so try_first_pass nullok
7 -auth [success=1 default=ignore] pam_systemd_home.so
8 auth [default=die] pam_faillock.so authfail
9 auth optional pam_permit.so
10 auth required pam_env.so
11 auth required pam_faillock.so authsucc
12 # If you drop the above call to pam_faillock.so the lock will be done also
13 # on non-consecutive authentication failures.
15 -account [success=1 default=ignore] pam_systemd_home.so
16 account required pam_unix.so
17 account optional pam_permit.so
18 account required pam_time.so
20 -password [success=1 default=ignore] pam_systemd_home.so
21 password required pam_unix.so try_first_pass nullok shadow sha512
22 password optional pam_permit.so
24 session required pam_limits.so
25 session required pam_unix.so
26 session optional pam_permit.so