A are administrative users who may be granted special privileges which are not available to non-root users (e.g., the ability to bind to the server in lockdown mode). By default a inherits the default set of privileges defined in the Root DN configuration. ds-cfg-root-dn-user top Specifies one or more alternate DNs that may be used to bind to the server as this root user. This root user will only be allowed to bind using the DN of the associated configuration entry. ds-cfg-alternate-bind-dn