#%PAM-1.0

auth        required      pam_env.so
auth        sufficient    pam_winbind.so krb5_auth krb5_ccache_type=FILE cached_login try_first_pass
auth        sufficient    pam_unix.so likeauth nullok use_first_pass
auth        required      pam_deny.so

account     sufficient    pam_winbind.so
account     required      pam_unix.so

password    requisite     pam_pwquality.so try_first_pass local_users_only
password    sufficient    pam_unix.so nullok use_authtok md5 shadow
password    sufficient    pam_winbind.so use_authtok
password    required      pam_deny.so

session     required      pam_mkhomedir.so silent skel=/etc/skel/ umask=0077
session     required      pam_limits.so
-session     optional      pam_systemd.so
session     required      pam_unix.so
