When enabling anonymous reads (cn=directory server: dsHeuristcs=0000002), and the internal DNS is enabled, by default the anonymous bind should not be able to read any objects. However, when dsHeuristics is set to allow anonymous samba 4.8.0 allows anonymous to read the state of the root dns server configuration. To reproduce: * install s4.8.0 with internal_dns enabled * allow anonymous reads * perform an anonymous read on the default naming context