Until patch is applied, the work-around is to specify
user_tree_dn = ou=Users,cn=example,cn=com tenant_tree_dn = ou=Tenants,cn=example,cn=com role_tree_dn = ou=Roles,cn=example,cn=com
in keystone.conf
Until patch is applied, the work-around is to specify
user_tree_dn = ou=Users, cn=example, cn=com cn=example, cn=com cn=example, cn=com
tenant_tree_dn = ou=Tenants,
role_tree_dn = ou=Roles,
in keystone.conf