Comment 1 for bug 1658641

Revision history for this message
Lance Bragstad (lbragstad) wrote :

I did some checking with other keystone developers that are a bit more familiar with keystone+LDAP integration [0]. It sounds like the short answer is that keystone doesn't support inspecting group assignment changes on the LDAP side.

We could clarify that in our LDAP documentation though.

[0] http://eavesdrop.openstack.org/irclogs/%23openstack-keystone/%23openstack-keystone.2017-01-23.log.html#t2017-01-23T20:20:56