HTTP 401 error on role add with Keystone V3 API


I've configured a keystone installation with Keystone V3 API and multiple domain backends(but there is only the Default domain yet). I copied v3cloudsamplpolicy.json to /etc/keystone/policy.json and edited to correct domain_id for cloud_admin.

When I try to assign a role to a user with admin token for example(of course I set the enviromental variables: OS_URL, OS_TOKEN, OS_IDENTITY_API_VERSION to correct values):

openstack role add --domain default --user admin admin

I get the following error:

The request you have made requires authentication.(HTTP401)

In the admin.log file I see the following error:

2015-05-26 11:24:27.810 1218 INFO keystone.common.wsgi [-] GET /users?name=admin
2015-05-26 11:24:27.810 1218 WARNING keystone.common.controller [-] RBAC: Bypassing authorization
2015-05-26 11:24:27.814 1218 DEBUG keystone.common.kvs.core [-] KVS region configuration for token-driver: {'keystone.kvs.backend': 'openstack.kvs.Memcached', 'keystone.kvs.arguments.distributed_lock': True, 'keystone.kvs.arguments.no_expiry_keys': ['revocation-list'], 'keystone.kvs.arguments.url': ['localhost:11211'], 'keystone.kvs.arguments.memcached_expire_time': 3600, 'keystone.kvs.arguments.memcached_backend': 'memcached', 'keystone.kvs.arguments.lock_timeout': 6} _configure_region /usr/lib/python2.7/dist-packages/keystone/common/kvs/
2015-05-26 11:24:27.819 1218 INFO keystone.common.kvs.core [-] Using default dogpile sha1_mangle_key as KVS region token-driver key_mangler
2015-05-26 11:24:27.822 1218 WARNING keystone.common.controller [-] Invalid token found while getting domain ID for list request
2015-05-26 11:24:27.824 1218 WARNING keystone.common.wsgi [-] Authorization failed. The request you have made requires authentication.

Same issue when I try to list roles of a user:

openstack role list --domain default --user admin

On the other hand I can create project, roles, domains.. I could really use some help on this. Thank you in advance!