how to configure the nss-pam-ldapd

Hi ,
I wan to force the users to change their password when they first login the clients by set the default  LDAP policy "pwdMustChange" and the User's attribute "pwdReset" to TRUE.
I have already configure the pam.d/system-auth and pam.d/password-auth, but it just denied the user to login, rather than let them change their password.
My system is Centos 7, nss-pam-ldapd 0.8.13, how should I configure the ldap.conf or nslcd.conf?



