Hi,
So thats a good first milestone to reach. Or almost reach - we still
need to put the gdm pam fixes into the repo (or rather, in upstream
gdm), and make the system boot to graphical.target by default.
So the PAM fixes
make sense anyway (because the GDM account doesn't
have a password and won't get locked), but this turns out to just
be an selinux issue. We should get the policy fixed and as a near
term workaround, put SELINUX=permissive in /etc/selinux/config