Instead of setting teh default umask at /etc/profile, let pam_umask.so do it's job. Also allow usergroups!