<filename>systemd-logind.service</filename>:</para>
<programlisting>#%PAM-1.0
-auth sufficient pam_unix.so
-auth required pam_deny.so
-
-account required pam_nologin.so
-account sufficient pam_unix.so
-account required pam_permit.so
-
-password sufficient pam_unix.so sha512 shadow try_first_pass try_authtok
-password required pam_deny.so
-
--session optional pam_loginuid.so
--session optional pam_systemd.so
-session required pam_unix.so</programlisting>
+auth sufficient pam_unix.so
+-auth sufficient pam_systemd_home.so
+auth required pam_deny.so
+
+account required pam_nologin.so
+-account sufficient pam_systemd_home.so
+account sufficient pam_unix.so
+account required pam_permit.so
+
+-password sufficient pam_systemd_home.so
+password sufficient pam_unix.so sha512 shadow try_first_pass try_authtok
+password required pam_deny.so
+
+-session optional pam_keyinit.so revoke
+-session optional pam_loginuid.so
+-session optional pam_systemd_home.so
+<command>-session optional pam_systemd.so</command>
+session required pam_unix.so</programlisting>
</refsect1>
<refsect1>