Configuring Administration Users. Directory Server contains default administration users, the Directory Manager and the cn=admin,cn=Administrators,cn=config user. Both of these users have the same access rights, but cn=admin,cn=Administrators,cn=config is subject to ACIs.. This section explains how to create an administration user with root access, and how to configure the Directory Manager.

After the admin resets the password of that user account, the attributes -- pwdAccountLockedTime & pwdFailureTime are removed./ldapsearch -h myhost -p 1389 -D "cn=directory manager" -j oud_pwd.txt -b dc=example,dc=com "cn=testuser" userpassword ds-pwp-password-policy-dn pwdHistory pwdChangedTime pwdAccountLockedTime pwdFailureTime ds-pwp-account-disabled pwdLockout …

