openstack-ansible /etc/keystone/ssl/certs/ empty

2016-12-23

seitan

2017-01-16

rbowen

Hello, I'm deploying my openstack system via openstack-ansible.
Everything works fine, but it seems that /etc/keystone/ssl/certs/ in keystone containers is empty.
I'm using rados to provide object storage to openstack.
According to
you need to generate certificates from /etc/keystone/ssl/certs/ for rados to be able to decode keystone messages.

I'm guessing because of that, rados fails to query keystone with the following errors:

2016-12-23 12:01:30.972648 7f5aaf7d6700  0 revoked tokens response is missing signed section
2016-12-23 12:01:30.972724 7f5aaf7d6700  0 ERROR: keystone revocation processing returned error r=-22

Is there any additional parameter I should use to in my ansible configuration to make those certificates be created?

my rados ceph.conf:

rgw_frontends = "civetweb port=80"
rgw keystone url =
rgw keystone admin user = ceph
rgw keystone admin password = secret
rgw keystone admin project = admin
rgw keystone admin domain = default
rgw keystone api version = 3
rgw keystone token cache size = 500
rgw keystone revocation interval = 500
rgw s3 auth use keystone = true
rgw keystone verify ssl = false

Thank you for your help.

1 answer

2017-01-17

seitan

2017-01-17

According to:

This is not an error and should be ignored.


