Global Password Policy

Use this information to work with the global password policy.

When a global password policy entry (cn=pwdpolicy,cn=ibmpolicies) is created by the server, the attribute ibm-pwdPolicy is set to FALSE, which is the default value. This aspect means that all password policy entries are ignored by the server. Only when the ibm-pwdPolicy attribute is set to TRUE the password rules are enforced by the server. When a global password policy is enforced and the ibm-pwdGroupAndIndividualEnabled attribute in cn=pwdpolicy,cn=ibmpolicies is set to TRUE, the group and individual password policies are also considered when you evaluate the password policy.
Note: A global administrative group member, primary administrator, and local admin group members with administrative control can enable or disable group and individual password policies.