Hide Forgot
Update the documentation to cover the 'nested group' use case: An AD user account might reside within a nested group, with authZ occurring against the parent AD group for keystone tenant access. It has been suggested that this entry in /etc/keystone/domains/keystone.[domain].conf will address this: ~~~ query_scope = sub ~~~
*** This bug has been marked as a duplicate of bug 1335696 ***