The user should be able to change his password when he can authenticate with a login/password. The password editor widget should be used (it verifies complexity of the password etc). A link to this form should be on his profile page.