A are administrative users who can granted special privileges that are not available to non-root users (for example, the ability to bind to the server in lockdown mode). By default a inherits the default set of privileges defined in the Root DN configuration. ds-cfg-root-dn-user top Specifies one or more alternate DNs that can be used to bind to the server as this root user. This root user is allowed to bind only using the DN of the associated configuration entry. ds-cfg-alternate-bind-dn