The PAM module for Trusted Extensions, pam_tsol_account.so.1, has only one module type and one function. The module is of type account, and the function checks the label range. The module has no options. No other Trusted Extensions-specific functions of PAM from Trusted Solaris 8 software are included in this release.
If a PAM stack for account in the Trusted Solaris 8 release did not have label_check_on in pam_tsol.so.1, then you do not need to add pam_tsol_account.so.1 to the corresponding stack in the Solaris Trusted Extensions release.
If a PAM stack for account in the Trusted Solaris 8 release did have label_check_on in pam_tsol.so.1, then the corresponding stack in the Solaris Trusted Extensions release should use pam_tsol_account.so.1 in the same place in the stack with no switches.
Trusted Extensions adds the allow_unlabeled option to PAM services. Together with the allow_remote option, administrators can manage headless systems remotely. For details, see the pam_roles(5) and pam_tsol_account(5) man pages.
PAM stacks for other module types should be used in the same manner for Trusted Extensions as for the Solaris OS. For more information, see the pam(3PAM) and pam.conf(4) man pages.