I need to support Mac clients who need to access a LDAP server to locate SMIME keys.
Since the keys are already in AD, and it's easy for me to create a RODC or read only forest where I push the certificates to, is it acceptable to expose unauthenticated LDAP and LDAPs to the internet?
One issue I can think of is an LDAP form of a directory harvest attack, where a spammer could determine which addresses are valid and which aren't.