Unable to create a tenant for an administrative user. Please help me [closed]

asked 2014-02-08 03:14:24 -0600

updated 2014-02-10 06:55:35 -0600


Is there any export who can help me to fix this issue.. This is very urgent for me to understand this kind of error. I am waiting for your response .. I had modified my keystone config file..

grep ^[^#] /etc/keystone/keystone.conf
admin_token = f17fa36e2167c95b8a54
log_file = /var/log/keystone/keystone.log
log_dir = /var/log/keystone
connection = mysql://keystone:labs#123@localhost/keystone
driver = keystone.identity.backends.sql.Identity
driver = keystone.credential.backends.sql.Credential
driver =
driver = keystone.catalog.backends.sql.Catalog
driver = keystone.token.backends.sql.Token
driver = keystone.policy.backends.sql.Policy
driver = keystone.contrib.ec2.backends.kvs.Ec2
token_format = UUID
methods = external,password,token,oauth1
password = keystone.auth.plugins.password.Password
token = keystone.auth.plugins.token.Token
oauth1 = keystone.auth.plugins.oauth1.OAuth
config_file = keystone-paste.ini
[ sql]
connection = mysql://keystone:labs#123@control/keystone

Initially I was getting below ''Unable to establish" error and the service was dead state..

[root@control ~]# export SERVICE_TOKEN=ADMIN
[root@control ~]# export SERVICE_ENDPOINT=http://control:35357/v2.0

[root@control ~]# keystone tenant-create --name=admin --description="Admin Tenant"
Unable to establish connection to http://control:35357/v2.0/tenants

[root@control ~]# /etc/init.d/openstack-keystone status
keystone dead but pid file exists

So I found the root cause for above as per below log and after I comment this line in conf file "keystone-paste.ini", still having same issue.. and as per log there are some Authorization failed.. Please please advise me if any modification require on this stage.

tail -f keystone.log
2014-02-09 15:56:43.971 1885 CRITICAL keystone [-] The Keystone paste configuration file keystone-paste.ini could not be found.
2014-02-09 15:58:39.156 1937 INFO keystone.common.environment [-] Environment configured as: eventlet
2014-02-09 15:58:40.154 1937 WARNING keystone.token.provider [-] keystone.conf [signing] token_format is deprecated in favor of keystone.conf [token] provider
2014-02-09 15:58:40.380 1937 INFO keystone.common.environment.eventlet_server [-] Starting /usr/bin/keystone-all on
2014-02-09 15:58:40.405 1937 INFO keystone.common.environment.eventlet_server [-] Starting /usr/bin/keystone-all on
2014-02-09 16:00:03.733 1937 WARNING keystone.common.wsgi [-] Authorization failed. The request you have made requires authentication. from
2014-02-09 16:05:34.703 1937 WARNING keystone.common.wsgi [-] Authorization failed. The request you have made requires authentication. from
2014-02-09 16:30:32.615 2031 INFO keystone.common.environment [-] Environment configured as: eventlet
2014-02-09 16:30:32.630 2031 CRITICAL keystone [-] No section 'admin' (prefixed by 'app' or 'application' or 'composite' or 'composit' or 'pipeline' or 'filter-app') found in config /etc/keystone/keystone.conf

[root@control ~]# /etc/init.d/openstack-keystone status
keystone (pid  1937) is running...

[root@control ~]# keystone tenant-create --name=admin --description="Admin Tenant"
Invalid OpenStack Identity credentials.

Advance Thanks to all,,,

Thanks all to view this link ... (more)

Closed for the following reason the question is answered, right answer was accepted by dheeru
close date 2014-02-10 11:36:31.636933



Did you set up service token and endpoint as suggested in official documentation ? Please refer the following link. If you still have issue, please let us know. We will help you to solve your issue

dheeru gravatar imagedheeru ( 2014-02-08 08:04:21 -0600 )edit

Thank you Dheeru for giving your attention.. Yes I have followed official documentation.. I am stuck in to define users, tenants, and roles on identity service. I have configured each step properly. Please advise me if is there any log location to troubleshoot the above error...

I updated below token as per my requirement.. Is this correct or please advise if I modify anything ..
# export OS_SERVICE_TOKEN=labs#123
# export OS_SERVICE_ENDPOINT=http://control:35357/v2.0

Thank you,,

Pradipta_OS_M gravatar imagePradipta_OS_M ( 2014-02-08 08:39:29 -0600 )edit

This surprised me. Can you ping me on ?

dheeru gravatar imagedheeru ( 2014-02-08 08:47:20 -0600 )edit

also look at the sample configuration posted by me in

dheeru gravatar imagedheeru ( 2014-02-08 10:44:04 -0600 )edit

Thank you for giving this link. I think it will help me to fix this issue. I will check today and I will post the update on this.. Thank you very much

Pradipta_OS_M gravatar imagePradipta_OS_M ( 2014-02-08 11:47:28 -0600 )edit

answered 2014-02-10 11:25:17 -0600

dheeru gravatar image

Had chat session with Pradipta. It was the issue of wrong admin_token. We created new admin_token using "openssl rand -hex 10" command. Also we verified that that other variables like OS_PASSWORD etc are not set in environment. After resetting the admin_token, able to create the

Hi, I am facing the same problem but under different scenario. I am trying to install keystone using CHEF but getting same error. Do you know how to resolve this in CHEF environment. Please help me in this regard. Thank you.

Ninad gravatar imageNinad ( 2014-05-09 01:21:35 -0600 )edit

Hi Ninad, I am also facing same issue in CHEF environment. If you got any help in this regard please help me.

monica-kharade gravatar imagemonica-kharade ( 2014-06-09 05:00:00 -0600 )edit

answered 2014-02-09 12:13:18 -0600

RomilGupta gravatar image

Hi ,

I faced the same issue yesterday I was not able to create a tenant from horizon via Administrative user, But I could able to create tenants and users via CLI. I really want to know what is the issue with Horizon.

Romil, Please give me the command and let me know the process how u can fix it with Horizon.. If you have a note on this then please send it to me

Pradipta_OS_M gravatar imagePradipta_OS_M ( 2014-02-09 20:00:57 -0600 )edit will send!

RomilGupta gravatar imageRomilGupta ( 2014-02-10 01:53:36 -0600 )edit

keystone service-delete your glance ID. I can see there are 2 ID used. remove one ID.

c3c6b999f5cf4dfc871019f3a8fd1e8a | glance | image
d8c36ce1cdb544c098f8b3f5d9332d3f | glance | image |

surisetty gravatar imagesurisetty ( 2014-09-17 06:30:40 -0600 )edit

