A is an administrative user who is granted special privileges which are not available to non-root users (for example, the ability to bind to the server in lockdown mode). By default, a inherits the default set of privileges defined in the Root DN configuration. ds-cfg-root-dn-user top Specifies one or more alternate DNs that may be used to bind to the server as this root user. This root user is only allowed to bind using the DN of the associated configuration entry. ds-cfg-alternate-bind-dn