Hi Sascha,
I had exactly the same problem as you. Im managing a server that was setup before my time, and it didn't even have the original password documented. This password was never required to add users (as I now have a new admin password that I use) - I've added many users since creating my new admin password on this server. I've recently updated the server to El Capitan and Server 5.015 and the issue began - I couldn't create users as I was not able to authenticate once inside the server app (adding a new user required logging into the LDAPv3 node and none of my username password combos worked).
I changed my account password, I rebuilt the keychain and I tried a lot of other things.
Finally I had success logging into the LDAPv3 node (as described by Kevin Neal above) with diradmin (as the username) and a password that I guessed (that was obviously the original password for the server). Once I logged onto my server app (with my 'new' password), I could add users with diradmin and the 'old' password. I guess I was lucky to find that password!
Although I think you can reset the open directory password this way, OS X Server: How to reset the Open Directory administrator password - Apple Support if you ever need to, but I didm't need to try that in the end.