pam_unix nonexistent user vs. invalid password

can I differ between nonexistent user and invalid password in pam.conf?

I want invalid user to be left for next authentication module, but invalid
password to be rejected, so other people can not override password I set for
local users.

I currently have:

auth    [success=2 default=ignore] nullok_secure

I have tried to add "auth_err=die" but that caused remot logins to be
refused too...

Thank you.
Matus UHLAR - fantomas, uhlar@xxxxxxxxxxx ;
