| # |
| # /etc/pam.d/common-auth - authentication settings common to all services |
| # |
| # This file is included from other service-specific PAM config files, |
| # and should contain a list of the authentication modules that define |
| # the central authentication scheme for use on the system |
| # (e.g., /etc/shadow, LDAP, Kerberos, etc.). The default is to use the |
| # traditional Unix authentication mechanisms. |
| # |
| |
| auth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=600 root_unlock_time=600 |
| auth sufficient pam_unix.so nullok try_first_pass |
| auth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root root_unlock_time=600 |