The password server (/servers/password) runs as root and hands out authorization tags after receiving the correct password. The ids corresponding to the authentication port match the unix user and group ids.

Support for shadow passwords is implemented here. Several utilities make use of this server, so they don't need to be setuid root.