maybe this is the reason: shadowAccount is added by fds when you select Configuration Tab -> Password Expiration -> Pasword expires after ... as i have not select anything and changed Administartor, no shadowAccount was created for him, Then i added expiration and test user was fine What i failed was: i have not selected expiration passwords before changing Administrator (or anyone else) password isn't it? -m -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 190 bytes Desc: This is a digitally signed message part. Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20090714/27475ef8/attachment.bin