OpenLDAP replication 'credentials'

We will be using OpenLDAP with TLS, and also plan to use the OpenLDAP
replication as well.

I would like to keep plain text passwords out of config files.  We are
using the '{SSHA}' configuration option for the 'rootdn' configuration
variable.  Is there something similar that I can use for the replication

I considered using SASL, but SASL passwords are stored in plain text in the
SASL password database, so that would just move the problem to a different

I unsuccessfully tried using the '{SSHA}' configuration option for the
replication 'credentials'.

Is there a way to hash or encrypt the replication credentials without using

Thanks in advance of any replies,