Apologies for the lack of attention on that review; getting that in today and proposed for backport is my highest priority. If we can hold 2013.1.1 for keystone until this is considered for backporting, that would be much appreciated!
I want to be clear though, this patch is cutting a feature (multi-domain support for LDAP/AD) from stable/grizzly rather than fixing it; while the feature technically works, it doesn't satisfy the use case it was intended to solve and results in unnecessary post-configuration setup for LDAP/AD deployments that may not be possible in the real world. Trying to backport a real "fix" would require backporting new features that are currently still in the blueprint phase for Havana.