2 auth required pam_listfile.so item=user sense=deny file=/etc/security/blacklist.lightdm onerr=succeed
3 # Always let the greeter start without authentication
4 auth required pam_permit.so
5 auth include system-auth
7 account required pam_shells.so
8 account required pam_nologin.so
9 account required pam_access.so
10 # No action required for account management
11 account required pam_permit.so
12 account include system-auth
14 # Can't change password
15 password required pam_deny.so
17 session optional pam_keyinit.so force revoke
18 session include system-auth
19 session optional pam_console.so