Recently I recieved a requirement from our business users that users are able to change their passwords to last used passwords. Users should not be able to reuse previously used 5 passwords.
There is an optional attribute in OID: pwdInHistory.
The maximum number of used passwords are stored in the pwdInHistory attribute of a given entry. Passwords stored in pwdInHistory cannot be used as a new password until they are purged from it. The default is 0.
So to implement the requirement, add pwdInHistory optional attribute in password policy for the desired user/group and update with the no of last passwords that should be allowed to be updated as new passwords.(in my case its FIVE).