password required pam_deny.so
session required pam_loginuid.so
-session required pam_systemd.so kill-session-processes=1
+session required pam_systemd.so
session optional pam_keyinit.so force revoke
session required pam_succeed_if.so audit quiet_success user = xdm
session required pam_permit.so