New features for the PAM framework in the Oracle Solaris 11.2 release include the following:
The pam_unix_account module supports time-based access control to all or specified PAM services. Therefore, security-relevant operations that call PAM can be restricted to specific days and times. Optionally, you can provide a timezone. See the pam_unix_account(5) man page.
The keywords access_times and access_tz can be assigned to users and roles. Like all user security attributes, these keywords are supported in all name services. For more information, see the user_attr(4) man page.