/etc/security/pam_pkcs11/pam_pkcs11.conf:
# use_pkcs11_module = opensc;
use_pkcs11_module = rutoken; и описание модуля rutoken:
use_pkcs11_module = rutoken;
pkcs11_module rutoken {
ca_dir = /etc/security/pam_pkcs11/cacerts;
crl_dir = /etc/security/pam_pkcs11/crls;
module = /usr/lib64/librtpkcs11ecp.so;
cert_policy = subject;
description = "Rutoken ECP";
slot_description = "none";
}
use_mappers привести к виду:
use_mappers = digest, cn, pwent, uid, mail, subject, null, opensc;
# systemctl enable --now pcscd
#cp CA.pem /etc/security/pam_pkcs11/cacerts/$certutil -A -n 'Root CA' -t 'CT,C,C' -a -d /etc/pki/nssdb/ -i ./CA.pem
$mkdir /home/user/.eid/$cat CA.pem > /home/user/.eid/authorized_certificates
# control system-auth pkcs11

Примечание
# control system-auth local