# su: auth account session
auth       sufficient     pam_rootok.so 
auth       required       pam_unix.so
account    required       pam_group.so no_warn group=admin,wheel ruser root_only fail_safe
account    required       pam_unix.so no_check_shell
password   required       pam_unix.so
session    required       pam_launchd.so
