Connect how? Does the user visit your web app, submit a password change, then have you update the password on the server that's storing it? Why isn't the web app on that server? Why are you transmitting with only the password secured and not the whole transmission? More detailed information on why you're doing things this way would be helpful.