The command requires a domain scoped token. Did you set the environment variable so that OSC uses a domain scoped token? This can be done by providing OS_DOMAIN_NAME instead of OS_PROJECT_NAME.
-Lin On Wed, Jun 3, 2015 at 9:29 AM, Amy Zhang <amy.u.zh...@gmail.com> wrote: > Hi guys, > > I have installed Kilo and try to use identity v3. I am using v3 policy > file. I changed the domain_id for cloud admin as "default". As cloud admin, > I tried "openstack domain list" and got the error message saying that I was > not authorized. > > The part I changed in policy.json: > > "cloud_admin": "rule:admin_required and domain_id:default", > > > The error I got from "openstack domain list": > > ERROR: openstack You are not authorized to perform the requested action: > identity:create_domain (Disable debug mode to suppress these details.) > (HTTP 403) (Request-ID: req-2f42b1da-9933-4494-9b39-c1664d154377) > > Has anyone tried identity v3 in Kilo? Did you have this problem? Any > suggestions? > > Thanks > Amy > -- > Best regards, > Amy (Yun Zhang) > > __________________________________________________________________________ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > >
__________________________________________________________________________ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev