#%PAM-1.0
account    sufficient    pam_unix.so
account    required      pam_winbind.so

auth    requisite    pam_nologin.so
auth    required     pam_env.so
auth    sufficient   pam_unix.so nullok
auth    required     pam_winbind.so krb5_auth krb5_ccache_type=FILE cached_login try_first_pass

password    required    pam_cracklib.so retry=3
password    sufficient  pam_unix.so try_first_pass nullok sha512 shadow
password    required    pam_winbind.so use_authtok try_first_pass

session     optional      pam_mkhomedir.so skel=/etc/skel/ umask=0077
session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
-session     optional      pam_systemd.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
