What do you mean by "exim resets its own userid"? Are you referring to the fact that it does a setuid() and setgid() before accepting incoming mail?
Does this mean that all PAM clients must be suid as root? That seems like a rather silly limitation.