Slave server with invisible master server

I have ldap clients in two separate zones. I would like that the clients in one of them authenticate against the slave server with no connection to the master. But this prevents the users to change their passwords because the password modification can only be performed against the master server with the updateref directive.
Any ideas?