Installing IPA without TLS-e breaks LDAP connections in keystone
Issue
- Operations Team installed IPA across all Overcloud hosts manually. A few days later, after successfully performing an Openstack minor update, platform authentication is not working anymore for LDAP domains:
- it is not possible to access Openstack using LDAP credentials, getting authentication error
Environment
- Red Hat Openstack Platform (RHOSP) 16
- Keystone LDAP domain configured (using ldaps) and enabled
- IPA enabled at host level
- "TLS everywhere" (TLS-e) not enabled in the overcloud
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.