Document required capabilities to import SSH keys of created accounts

Change-Id: Ia9e75f12051adb08e40c60340a24b6205fec4dda
Signed-off-by: Edwin Kempin <edwin.kempin@sap.com>
diff --git a/src/main/resources/Documentation/about.md b/src/main/resources/Documentation/about.md
index e320dfe..b9cdb25 100644
--- a/src/main/resources/Documentation/about.md
+++ b/src/main/resources/Documentation/about.md
@@ -87,7 +87,10 @@
 For auth type 'LDAP', 'HTTP\_LDAP' or 'CLIENT\_SSL\_CERT\_LDAP' missing
 user accounts are automatically created. The public SSH keys of a user
 are automatically retrieved from the source Gerrit server and added to
-the new account in the target Gerrit server.
+the new account in the target Gerrit server. For this the remote user
+must have the link:access-control.html#capability_modifyAccount[Modify
+Account] or the link:access-control.html#capability_administrateServer[
+Administrate Server] capability assigned on the source system.
 
 Gerrit internal users (e.g. service users) are never automatically
 created but must be created in the target Gerrit server before the