NOTE:

The global and local password policies are mutually exclusive. That is, if a local password policy is defined and enabled for a subtree or user, Directory Server applies that policy during the bind process. In the absence of a local password policy, the server subjects the user to the global password policy. The password policy design requires sending the password policy request control with the bind request. The LDAP command-line option -gsuppresses sending this request control with the bind request.

For details about the -goption, check ldapsearch, ldapmodify, or ldapdelete utilities in the Configuration, Command, and File Reference.

8.6 Designing a password policy 111