I cannot imagine any reason why the password has a length limit. If one was suspicious one might think this indicated a poor/fragile/insecure login implementation.
To say nothing of checking the implementation uses at least something like salted hashes, I suggest allowing the user to enter any password they feel comfortable with.