diff --git a/ansible/roles/keystone/templates/wsgi-keystone.conf.j2 b/ansible/roles/keystone/templates/wsgi-keystone.conf.j2 index 83886415b0..6c6e96450c 100644 --- a/ansible/roles/keystone/templates/wsgi-keystone.conf.j2 +++ b/ansible/roles/keystone/templates/wsgi-keystone.conf.j2 @@ -78,6 +78,7 @@ LogLevel info {% for idp in keystone_identity_providers %} {% if idp.protocol == 'openid' %} + OIDCDiscoverURL {{ keystone_public_url }}/redirect_uri?iss={{ item.identifier | urlencode }} Require valid-user AuthType openid-connect