5aa1019010
modifying @pam users credentials should be only possible for root@pam, otherwise it can have unintended consequences. also enforce the same limit on user creation (except self_service check, since it makes no sense during user creation) Signed-off-by: Oguz Bektas <o.bektas@proxmox.com>