Pam authentication
The current mechanism in krdp requires the user to set up an additional username and password. This adds an extra step in getting set up, especially for a truly headless session. Using PAM makes it automatic from a user POV.
This will also help when we're running with the login manager as setting that up with arbitrary users would be weird.
It is exposed as a setting to the user in the existing KCM alongside the other arbitrary user list.