OUD replicating out to instance in DMZ and account locks
Hi,
this is on OUD 12.2.1.3.200623
We are trying to have an OUD instance in a DMZ that gets replicated data from an instance on the intranet. One specific concern is that it should not be possible to brute-force/crawl all users on the DMZ instance, try random passwords a couple of times for each, and by that lock all the accounts on the intranet. With ODSEE you would just have made the instance in the DMZ a consumer and that would have been it.
With OUD you can set the writability on the DMZ instance to internal-only. But given how a BIND is a kind of a read request that also sets some internal-only attributes depending on the password policy, that alone doesn't do the trick, and you also have to set the replication server that the DMZ instance talks to to untrusted.