In /etc/pam.d, there is one PAM file per service.
Syntax: module_type control_flag path_to_module_agent
auth — authentication.account — account-based restrictions (validity, time of day, etc.).session — things that run at login/logout.password — password updates.required — success needed; a failure is reported but only after the rest of the stack has run.requisite — like required, but a failure returns immediately without running the rest of the stack.sufficient — if this module succeeds, it is the last module tested in the stack.optional — its result is only taken into account if no other module succeeded or failed.[value=action value=action2 ...] — advanced control: map a module result to a specific action.Sample:
1account [default=bad \
2 success=ok \
3 user_unknown=ignore \
4 service_err=ignore \
5 system_err=ignore \
6 authinfo_unavail=ignore] /lib/security/$ISA/pam_ldap.so
1# /etc/pam.d/password-auth
2auth required pam_env.so
3auth required pam_faillock.so preauth silent audit deny=5
4auth sufficient pam_unix.so nullok try_first_pass
5auth [default=die] pam_faillock.so authfail audit deny=5
6auth sufficient pam_faillock.so authsucc audit deny=5
7auth requisite pam_succeed_if.so uid >= 1000 quiet_success
8auth required pam_deny.so
9
10account required pam_access.so
11account required pam_faillock.so
1faillock --user <user> # show the failed-login counter.
2faillock --user <user> --reset # reset it.
pam_faillock is the modern replacement for the deprecated pam_tally2.