How to use multiple ldap url in keystone.conf for HA

asked 2015-05-04

updated 2015-05-04

I want to use LDAP HA with keystone. I have two LDAP server which are replica of each other. I want to specify both LDAP server in the keystone.conf so if one server fails request should go to send second LDAP server.

For example in generic ldap.conf we can specify the multiple LDAP server delimited by space URI <ldap[si]://[name[:port]] ...>

1 answer

answered 2015-05-04

updated 2015-05-04

In case of LDAP HA server, you need to configure the Virtual IP in your keystone configuration file. You can use HAProxy, Piranha etc for load balancing.

Thanks for the reply Does this means keystone does not support multiple ldap url in its configuration ? Sorry but i don't understand how to achieve same using HAProxy or any other load balancer.

deeghuge ( 2015-05-06 )

Not sure whether keystone.conf supports multiple LDAP urls. However in keystone/keystone/common/ldap/ I did not find any code block for parsing multiple LDAP urls.

uts9 ( 2015-05-06 )

Regarding HAProxy configuration you can follow the steps provided in this article. link text

uts9 ( 2015-05-06 )

