auth     required  pam_env.so
auth     required  pam_succeed_if.so audit quiet_success user = gdm
auth     optional  pam_permit.so

account  required  pam_succeed_if.so audit quiet_success user = gdm
account  optional  pam_permit.so

password required  pam_deny.so

session  optional  pam_keyinit.so force revoke
session  required  pam_succeed_if.so audit quiet_success user = gdm
session  required  pam_systemd.so
session  optional  pam_permit.so
