/usr/share/doc/libpam-afs-session/examples/common-account is in libpam-afs-session 2.5-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 | # /etc/pam.d/common-account -- Authorization settings common to all services.
#
# This file is included from other service-specific PAM config files on
# Debian, and should contain a list of the authorization modules that define
# the central access policy for use on the system.
#
# Deny service to users whose accounts are expired in /etc/shadow and check
# krb5_kuserok for logins via Kerberos.
account required pam_unix.so
account required pam_krb5.so
|