maybe this is the reason:
shadowAccount is added by fds when you select
Configuration Tab -> Password Expiration -> Pasword expires after ...
as i have not select anything and changed Administartor, no shadowAccount was
created for him,
Then i added expiration and test user was fine
What i failed was:
i have not selected expiration passwords before changing Administrator (or
anyone else) password
isn't it?
-m