Bug 1427533 - Need to better document that Directory Manager bypasses password policies
Summary: Need to better document that Directory Manager bypasses password policies
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Directory Server
Classification: Red Hat
Component: Doc-administration-guide
Version: 10.0
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
: ---
Assignee: Marc Muehlfeld
QA Contact: Viktor Ashirov
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-02-28 14:24 UTC by mreynolds
Modified: 2017-03-15 08:51 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-03-15 08:51:25 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description mreynolds 2017-02-28 14:24:43 UTC
There is a lot of confusion around password policies and the Directory Manager account.  The Directory Manager account bypasses password policies, but there are so many people who use directory manager to manage user's passwords.  Then they get upset because password policies are not working as they expect.

This is mentioned here:

https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/User_Account_Management.html#Managing_the_Password_Policy-Setting_User_Passwords

But I think we should change the wording to stop using "root DN":

----------------------
Warning
Because password administrators and the root DN are not bound by password policy and syntax, they should not be used for user password management. You should only use these types of accounts to perform special password administration tasks that require violating the password policy. 

...
----------------------

Change to:

----------------------
Warning
Password administrators and the "Directory Manager", or Root DN, are not bound by password policy and syntax.  This means these accounts completely bypass all password polices.  These accounts should not be used for regular user password management.  You should only use these accounts to perform special password administration tasks that require violating the password policies. 

-----------------------

Due to the fact that so many people are still making this mistake I think we should also add a duplicate warning to the start page of password policy doc:

https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/User_Account_Management.html#User_Account_Management-Managing_the_Password_Policy

Comment 2 Marc Muehlfeld 2017-03-15 08:51:25 UTC
The update is now available on the Customer Portal.


Note You need to log in before you can comment on or make changes to this bug.