I know that the policy doesn't apply to the root user, but I'm not changing the root user password, I'm changing the password of another user. Surely the policy should apply !