TL;DR allow dudas to login despite /etc/nologin
Accounts that are in the "adm" group might have a good reason to login even if /etc/nologin is in effect.
So skip the nologin pam module for those.
I tried the sshd part by manually editing the /etc/pam.d/sshd
on a live system.
BUT I did not test the general login
one!
https://git.gsi.de is provided by CIT→Linux&Web | GSI Helmholtzzentrum fuer Schwerionenforschung GmbH | Imprint (in German) | Privacy policy