I'm working with a user account called "test3" on this system. I open 2 ssh sessions to the server named "api01r5v" and run tail -f /var/log/secure in one session while logging in as test3 in the second session and then try to change the password. I did the same thing with /var/log/messages. Nothing is logged to either file. So ran "grep -r test3 /var/log" to do a recursive search for the user account. I find the following in /var/log/audit/audit.log:
type=USER_CHAUTHTOK msg=audit(1352299927.019:4811): user pid=4001 uid=512 auid=512 subj=user_u:system_r:unconfined_t:s0 msg='PAM: chauthtok acct="test3" : exe="/usr/bin/passwd" (hostname=?, addr=?, terminal=pts/2 res=failed)'
Looks like chauthtok is failing, but I don't know why.