@%@UCRWARNING=# @%@

@include common-auth
@!@
scope = "sshd"
accessfileFlag = "auth/%s/restrict" % (scope,)
if configRegistry.is_true(accessfileFlag, False):
    accessfileDefault = "/etc/security/access-%s.conf" % (scope,)
    accessfileKey = "auth/%s/accessfile" % (scope,)
    accessfile = configRegistry.get(accessfileKey, accessfileDefault)
    line = [
        'account required pam_access.so',
        'accessfile=%s' % (accessfile,),
        'listsep=,',
    ]
    maxent = configRegistry.get('pamaccess/maxent', False)
    if maxent:
        line.append('maxent=%s' % (maxent,))
    print(' '.join(line))
@!@
@include common-account
@include common-session
session    optional   pam_mail.so standard noenv
@!@
if not configRegistry.is_true('system/setup/showloginmessage', False):  # The welcome message in appliance mode has precedence
    if configRegistry.is_true('sshd/motd', True):
        print('session optional pam_motd.so motd=/etc/welcome.msg')
@!@
@include common-password
