RH Directory Server provides a functionality named retroChangelog that records in a file an attribute with the password in clear text. The attribute is named *unhashed#user#password*. This allows any administrator, having the rights to read (dump) the database, to retrieve the password in clear text.
Created 389-ds-base tracking bugs for this issue: Affects: fedora-all [bug 1592225]
Closing as duplicate of 1591480 : it is the same nsslapd-unhashed-pw-switch attribute that regulates both retroChangelog & replica plugins behavior. *** This bug has been marked as a duplicate of bug 1591480 ***