I seem to remember from back when I still had a KACE system that the input fields in KACE’s LDAP configuration were rather limited regarding the password length (or something like that) — e.g. only 12 or 16 characters. As far as I remember there wasn’t a workaround. What I ended up doing was adding a separate user just for KACE (it’s only about searching the LDAP anyway) whose password length matches what KACE accepted.