>is it possible to limit CHOWN capability (in max_caps) or CHOWN in general
>with some uids/gids? Like AUTH Capabilities, where you can define uids.

Do you mean using
attr_set_user CAP <UID> max_cap CHOWN    (or giving a list of desired 
capabilities for each individual user)?

