But the succeed_if module is also nice since you don't need a configuration file: # PAM configuration for rsh - /etc/pam.d/rsh # SLES 9 auth required pam_rhosts_auth.so no_rhosts auth required pam_nologin.so auth required pam_succeed_if.so user ingroup petromo