I have setup multi domain environment and do delegation to domain admin. Domain admin can see all things inside its own domain and can manage projects inside its own domain. But, domain admin cannot create users inside its own domain. It seem something wrong with "rule:admin_and_matching_user_domain_id" which is related to "user.domain_id". What is happen on my case?

Best regards,

What makes you think something is wrong with this rule? What are the symptoms? What messages do you find in Horizon's and Keystone's log files? What do you get when you use the CLI openstack --debug user create?

Hi Bernd,

There in no Create button on Users menu of Horizon if I login with domain admin.

Best regards,

Can it be you have hit the bugs solved be this commit: https://git.openstack.org/cgit/openst...

the bugs are reported here: https://bugs.launchpad.net/ubuntu/+so... https://bugs.launchpad.net/ubuntu/+so...

