Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 1519057 - OSP11->OSP12 Keystone LDAP Domain Template No Longer Works
Summary: OSP11->OSP12 Keystone LDAP Domain Template No Longer Works
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates
Version: 12.0 (Pike)
Hardware: x86_64
OS: Linux
Target Milestone: z1
: 12.0 (Pike)
Assignee: Harry Rybacki
QA Contact: Prasanth Anbalagan
Depends On:
TreeView+ depends on / blocked
Reported: 2017-11-30 01:45 UTC by Will Kline
Modified: 2018-03-23 01:44 UTC (History)
13 users (show)

Fixed In Version: openstack-tripleo-heat-templates-7.0.3-19.el7ost
Doc Type: Known Issue
Doc Text:
There is currently a known issue with LDAP integration for Red Hat OpenStack Platform. At present, the `keystone_domain_confg` tag is missing from `keystone.yaml`, preventing Puppet from properly applying the required configuration files. Consequently, LDAP integration with Red Hat OpenStack Platform will not be properly configured. As a workaround, you will need to manually edit `keystone.yaml` and add the missing tag. There are two ways to do this: 1. Edit the file directly: a. Log into the undercloud as the stack user. b. Open the keystone.yaml in the editor of your choice. For example: `sudo vi /usr/share/openstack-tripleo-heat-templates/docker/services/keystone.yaml` c. Append the missing puppet tag, `keystone_domain_confg`, to line 94. For example: `puppet_tags: keystone_config` Changes to: `puppet_tags: keystone_config,keystone_domain_confg` d. Save and close `keystone.yaml`. e. Verify you see the missing tag in the `keystone.yaml` file. The following command should return '1': `cat /usr/share/openstack-tripleo-heat-templates/docker/services/keystone.yaml | grep 'puppet_tags: keystone_config,keystone_domain_config' | wc -l` 2. Or, use sed to edit the file inline: a. Login to the undercloud as the stack user. b. Run the following command to add the missing puppet tag: `sed -i 's/puppet_tags\: keystone_config/puppet_tags\: keystone_config,keystone_domain_config/' /usr/share/openstack-tripleo-heat-templates/docker/services/keystone.yaml` c. Verify you see the missing tag in the keystone.yaml file The following command should return '1': `cat /usr/share/openstack-tripleo-heat-templates/docker/services/keystone.yaml | grep 'puppet_tags: keystone_config,keystone_domain_config' | wc -l`
Clone Of:
Last Closed: 2018-01-30 21:24:32 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Priority Status Summary Last Updated
Launchpad 1737799 None None None 2017-12-12 18:01:13 UTC
OpenStack gerrit 527485 None None None 2017-12-13 16:09:33 UTC
OpenStack gerrit 527758 None None None 2017-12-13 19:13:22 UTC
Red Hat Product Errata RHBA-2018:0253 normal SHIPPED_LIVE Red Hat OpenStack Platform 12.0 director Bug Fix Advisory 2018-02-16 03:41:33 UTC

Description Will Kline 2017-11-30 01:45:21 UTC
Description of problem:
The Keystone LDAP domain template that was working for our deployment in OSP11 no longer works in our OSP12 test deployments.  It does not appear to generate any of the config files necessary (/etc/keystone/domains/ on the host or on inside the keystone container.  Inside the keystone container, I ran "grep -r 'uid=keystone.user,cn=users,cn=compat' /", and got no results.

I have based my template off of and this works fine on OSP11.

Version-Release number of selected component (if applicable):
Installed Packages
Name        : openstack-tripleo-heat-templates
Arch        : noarch
Version     : 7.0.3
Release     : 0.20171024200823.el7ost

How reproducible:
Deploy a basic OpenStack using 12-beta, and include the keystone_domain_specific_ldap_backend.yaml that has been customized for your ldap domain. 

Actual results:

After sourcing the overcloudrc.v3, the following commands work:
"openstack domain list" lists "default" and "my-domain"
"openstack user list --domain my-domain" lists no users

Expected results:
"openstack domain list" lists "default" and "my-domain"
"openstack user list --domain my-domain" lists all of the users matching my ldap user_tree

Comment 4 Alex Schultz 2017-12-12 17:59:15 UTC
We appear to be missing the keystone_domain_config tag from the docker configuration so that the domain config is never written out during the deployment.

The later step3 where we do run it is for resource configurations and not part of the configuration generation

Comment 5 Harry Rybacki 2017-12-13 16:09:33 UTC
Moving to POST as upstream review[1] has merged.

[1] -

Comment 6 Nathan Kinder 2017-12-13 19:07:19 UTC
A stable/pike backport has been proposed here:

Comment 7 Alex Schultz 2017-12-14 15:59:55 UTC
Upstream stable backport has merged

Comment 10 Prasanth Anbalagan 2018-01-23 17:45:33 UTC
As expected, the config files are generated under /etc/keystone/domains.

(undercloud) [stack@undercloud-0 ~]$ rpm -qi openstack-tripleo-heat-templates.noarch
Name        : openstack-tripleo-heat-templates
Version     : 7.0.3
Release     : 21.el7ost
Architecture: noarch
Install Date: Tue 23 Jan 2018 09:33:23 AM EST

[heat-admin@controller-0 ~]$ sudo ls -l /var/lib/config-data/puppet-generated/keystone/etc/keystone/domains
total 4
-rw-r--r--. 1 root root 942 Jan 23 17:14 keystone.freeipadomain.conf
[heat-admin@controller-0 ~]$

Comment 15 errata-xmlrpc 2018-01-30 21:24:32 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

Note You need to log in before you can comment on or make changes to this bug.