When using RADIUS as system user-auth backend this does not apply to the console-server which uses dropbear for the SSH to RS232 mapping.
- /sbin/radius_shell was not listed as an allowed shell (https://github.com/vyos/libpam-radius-auth/commit/624b27867fbae8)
- dropbear returns: Feb 14 14:56:15 vyos dropbear[4844]: User account 'username' is locked