I"m putting this in an answer because the character count limit on comments is too low.

I'm convinced I have an authentication problem and I'm worried it's because of domain name. When I created the 'cinder' user it was with '--domain default'. When I list my domains I have a domain with ID = 'default' and name = 'Default'. So my questions are:

  1. Is domain name matching case sensitive?
  2. Is domain name matching on the name or the ID?
  3. Should I be looking elsewhere?
  4. Can I coerce Keystone into telling me exactly why the authentication failed?