We are working on the security of the appliance using acl and ace. We have denied access for everyone globally and are adding permissions in the group level for our users to access the appliance.
The problem that I have not been able to figure out is what permissions are needed for a user to be able to change their password.
Write access to the user is needed to change the password for a user, so if you Add a User ACE with the User and Trustee the same, and Read/Write perms.