We should fill the real principal of user that administratively changed a password of some other principal (for audit purposes). Now, we just enter a fixed principal root/admin@REALM.
root/admin@REALM
# kadmin.local -q "getprinc admin@IDM.LAB.BOS.REDHAT.COM" Authenticating as principal admin/admin@IDM.LAB.BOS.REDHAT.COM with password. Principal: admin@IDM.LAB.BOS.REDHAT.COM ... Last modified: Fri Mar 29 04:29:20 EDT 2013 (root/admin@IDM.LAB.BOS.REDHAT.COM) ...
Changing component, the patch would rather consist of ipa-pwd-extop plugin change.
ipa-pwd-extop
Metadata Update from @mkosek: - Issue assigned to someone - Issue set to the milestone: Future Releases