It shouldn't matter how long your password is, it should be salted, securely hashed and only then stored. Storing the hash and salt always takes a fixed maximal amount of space, so changing the DB is likely something which should only be done once.