Open
Description
I just flipped a user from profile_pam_access::allow_rules to profile_pam_access::deny_rules. The new deny rule was after the pre-existing allow rule, which defeats the purpose.
I definitely do not understand pam_access position parameters, but it seems weird/odd to have deny rules always be the last in the access.conf file.