Forcing an add or update for an entry
You can know more about the procedure of forcing an add or update for an entry through the information provided here.
When an administrative user updates or adds an entry, specifying a password policy operational attribute as one of the attributes to be changed or in the case of a new entry, the administrative user specifies a value for one or more of the operational attributes, then the administrative user is performing a forced add/update for the entry.
A forced add/update of an entry means that the normal password policy processing is not performed for that entry. Only those password policy operational attributes specified on the operation are changed as indicated.
Normally the forced add/update is indicated by using the administrative control on the operation while specifying a password policy attribute.
When updating the ibm-pwdAccountLocked attribute, the administrative control does not need to be sent.
When the administrator is performing a forced add/update to an entry, the administrator has the intention to set all of the password policy attributes as the entry requires.
Do not force an add unless all of the normal password policy operational attributes have been given an appropriate value, such as pwdReset and pwdChangedTime.If pwdChangedTime is not given a value on a forced add, then this attribute is not set until the user first attempts to bind to the server, or until another forced update creates a time for this attribute.
If any of the password policy attributes need to be specifically set on an add operation, the new entry should be created first and aseparate modify operation should be used to set any other password policy attribute.
If the userpassword attribute is being modified on the modify operation, then any password policy attributes that are to be force updated must be updated separate from the userpassword modification operation. This ensures that all of the proper password policy changes that occur on an add or modify operation are performed.