#%PAM-1.0
auth     sufficient	pam_tcb.so shadow fork prefix=$2a$ count=8 nullok
auth     requisite	pam_succeed_if.so uid >= 500 quiet
auth     required	pam_ldap.so use_first_pass

account  sufficient	pam_tcb.so shadow fork
account  required	pam_ldap.so

password required	pam_passwdqc.so config=/etc/passwdqc.conf
password sufficient	pam_tcb.so use_authtok shadow fork prefix=$2a$ count=8 nullok write_to=tcb
password requisite	pam_succeed_if.so uid >= 500 quiet
password required	pam_ldap.so use_authtok

session  optional	pam_tcb.so
session  optional	pam_ldap.so
session  required	pam_mktemp.so
session  required	pam_limits.so
