#%PAM-1.0 # pam_selinux.so close should be the first session rule -session required pam_selinux.so close session required pam_loginuid.so -session required pam_selinux.so open session required pam_namespace.so session optional pam_keyinit.so force revoke session required pam_limits.so -session optional pam_systemd.so session required pam_unix.so -session optional pam_reauthorize.so prepare