# Begin /etc/pam.d/su

auth        sufficient      pam_rootok.so
auth        required        pam_unix.so
auth        optional        pam_faildelay.so delay=1000000

# Si su es hacia el usuario root, uso un entorno especial para root
auth        [default=1 success=ignore]        pam_succeed_if.so quiet uid eq 0
auth        optional        pam_env.so debug envfile=/etc/security/environment.root

account     required        pam_unix.so
session     optional        pam_mail.so     dir=/var/mail standard
session     optional        pam_xauth.so
session     required        pam_env.so
session     required        pam_unix.so

# End /etc/pam.d/su
