The UCS manual should mention that the "Password expiry interval" in the UDM password policy must be set empty (i.e. not to 0) to disable password expiry.
A similar comment could be added for the maxiumum password age property of the samba domain object (IIRC empty or "-1" in that case. I guess "0" would effectively disable logins).
Documented in Chapter 5.2 "Policy-based password management" The setting in the Samba domain object was already documented.
Ok, well phrased: "If this input field is left blank, no password expiry interval is applied." This leaves room for the new adjustment of Bug 29918.