[openstack-dev] Kilo v3 identity problems

Lin Hua Cheng os.lcheng at gmail.com
Wed Jun 3 18:00:02 UTC 2015


The command requires a domain scoped token.

Did you set the environment variable so that OSC uses a domain scoped
token? This can be done by providing OS_DOMAIN_NAME instead of
OS_PROJECT_NAME.

-Lin

On Wed, Jun 3, 2015 at 9:29 AM, Amy Zhang <amy.u.zhang at gmail.com> wrote:

> Hi guys,
>
> I have installed Kilo and try to use identity v3. I am using v3 policy
> file. I changed the domain_id for cloud admin as "default". As cloud admin,
> I tried "openstack domain list" and got the error message saying that I was
> not authorized.
>
> The part I changed in policy.json:
>
> "cloud_admin": "rule:admin_required and domain_id:default",
>
>
> The error I got from "openstack domain list":
>
> ERROR: openstack You are not authorized to perform the requested action:
> identity:create_domain (Disable debug mode to suppress these details.)
> (HTTP 403) (Request-ID: req-2f42b1da-9933-4494-9b39-c1664d154377)
>
> Has anyone tried identity v3 in Kilo? Did you have this problem? Any
> suggestions?
>
> Thanks
> Amy
> --
> Best regards,
> Amy (Yun Zhang)
>
> __________________________________________________________________________
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe: OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20150603/fc7d4f3d/attachment.html>


More information about the OpenStack-dev mailing list