Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.
The system must use a strong hashing algorithm to store the password.
Check
Verify that the pam_unix.so module is configured to use sha512 in /etc/pam.d/password-auth with the following command: