class pam {
  if $pam != false {
    # pam - login
    file { "/etc/pam.d/login":
      source  => "puppet://$server/modules/nodo/etc/pam.d/login",
      owner   => "root",
      group   => "root",
      mode    => 0644,
      ensure  => present,
    }

    # pam - gdm
    file { "/etc/pam.d/gdm":
      source  => "puppet://$server/modules/nodo/etc/pam.d/gdm",
      owner   => "root",
      group   => "root",
      mode    => 0644,
      ensure  => present,
    }

    # pam - mountpoints
    file { "/etc/security/pam_mount.conf.xml":
      ensure  => present,
      owner   => root,
      group   => root,
      mode    => 0644,
      source  => "puppet://$server/files/etc/security/pam_mount.conf.xml",
    }
  }
}