v1.1.1
Sets ldap_group_nesting_level = 5 so SSSD walks nested groups itself when pointed at a server without the nestgroup overlay (no OpenLDAP 2.6.x release ships it). Against the SSO's bundled slapd the existing memberof= access filter is already transitive, so SSH login inherits nesting for free.