Under the section, "Configuring the LDAP Identity Provider", there are several references for
"cn=openstack,cn=org" which should change to "dc=openstack,dc=org"
Also, there is an inconsistent entry for 'Roles' under "The corresponding entries in the Keystone configuration file are".
role_tree_dn = ou=Roles,dc=example,dc=com is wrong and should reflect what is mentioned in the "Configuring the LDAP Identity Provider" i.e. it should be, role_tree_dn = ou=Roles,dc=openstack,dc=org
The keystone doc has an incorrect entry for the role_tree_dn as bried below and can be viewed at the following link: docs.openstack. org/developer/ keystone/ configuration. html
http://
Under the section, "Configuring the LDAP Identity Provider", there are several references for cn=org" which should change to "dc=openstack, dc=org"
"cn=openstack,
Also, there is an inconsistent entry for 'Roles' under "The corresponding entries in the Keystone configuration file are". dc=example, dc=com is wrong and should reflect what is mentioned in the "Configuring the LDAP Identity Provider" i.e. it should be, role_tree_dn = ou=Roles, dc=openstack, dc=org
role_tree_dn = ou=Roles,