#%PAM-1.0
#
# pam.d/su - PAM su configuration from EAL3/CAPP compliance
#		see the Evaluated Configuration Guide for more info
#

auth       sufficient   pam_rootok.so
auth       required     pam_wheel.so use_uid
auth       required     pam_stack.so service=system-auth

account    required     pam_stack.so service=system-auth

password   required     pam_deny.so

session    required     pam_stack.so service=system-auth
session    optional     pam_xauth.so
