Oracle Unified Directory tns resolution only - security concerns
We are moving towards the use of Oracle Unified Directory (currently using OID). Our security team has mentioned that this tool brings up many security concerns where they feel it isn't appropriate to move forward with it (and has the same concerns with OID).
Basically all we're using the tool for is TNS resolution (tnsnames.ora replacement). The way we have it configured is anonymous binds from the clients requesting a tns resolution over non-ssl. The security team complains that we need authentication (no anonymous binds) and a way to limit the information to known clients (only hand out info to those that need it, and only the information they need - no more, no less). I've explained that this is not how the utility works. Can someone help confirm that my understandings are correct and what the security team is asking for simply isn't