cri_models: add support for changing LDAP objects userPassword attributes
Some LDAP accounts may not have any Kerberos principal associated with them, we need a way to set a password for theses account.
Alternatively, for Kerberos authentication via SASL, we need to set the userPassword
attribute to {SALS}$KERBEROS_PRINCIPAL