I suggest you just rethink all this. The simplest way to achieve what you're after is already built-in, just set up client authn to leverage LDAP in the same way the IdP supports it for users. The LDAP bind will take care of keeping the password out of plain text. -- Scott