#%PAM-1.0

# Block login for root (in GUI through sddm)
auth         required      pam_succeed_if.so user != root quiet_success

auth         substack      system-auth
-auth        optional      pam_gnome_keyring.so
-auth        optional      pam_kwallet5.so
-auth        optional      pam_kwallet.so
auth         include       postlogin
account      required      pam_nologin.so
account      include       system-auth
-password    optional      pam_gnome_keyring.so use_authtok
password     include       system-auth
session      required      pam_loginuid.so
session      optional      pam_keyinit.so force revoke
session      required      pam_namespace.so
-session     optional      pam_gnome_keyring.so auto_start
-session     optional      pam_kwallet5.so auto_start
-session     optional      pam_kwallet.so auto_start
session      include       system-auth
session      include       postlogin
