Did you do the password change as the root user or the account owner? I'm not sure that the user account would have the privileges required to change their password type (for security).
The overall configuration looks fine; those are some mighty large allowed uploads, do you do a lot of photo or PDF uploads?