#%PAM-1.0 auth sufficient pam_rootok.so auth sufficient pam_sss.so forward_pass auth required pam_unix.so account [default=bad success=ok user_unknown=ignore authinfo_unavail=ignore] pam_sss.so account required pam_unix.so -session required pam_mkhomedir.so skel=/etc/skel umask=0077 session required pam_unix.so session optional pam_sss.so password include system-auth