AD connector reset password on port 389

As we know AD connector password operation does not work without  Secure connection (port 636 ). 

Because it pass encrypted  password for reset password operation .



i am looking some workaround and alternative solution here to do password operation with port 389 or 636 without certificate  ,


As customer has some legacy AD domain(windows 2000 server ) which does not have certificate services running and we need certificate to connect with port 636 .

(even they do not have  have old certificate which we can utilise it with skip certificate validation feature )