Append the following to /etc/pve/lxc/<vmid>.conf of an unpriviledged containers.
/etc/pve/lxc/<vmid>.conf
features: keyctl=1,nesting=1