# Pastebin MPGzn1l1 sorin-mihai: if using self signed, be sure to set: kolla_enable_tls_internal: "yes" kolla_verify_internal_ca_certs: "no" kolla_copy_ca_into_containers: "yes" and set openstack_cacert as well {% if base_distro == "ubuntu" or base_distro == "debian" %} openstack_cacert: "/usr/local/share/ca-certificates/kolla-customca-haproxy-internal.crt" {% endif %} {% if base_distro == "centos" %} openstack_cacert: "/etc/pki/ca-trust/source/anchors/kolla-customca-haproxy-internal.crt" {% endif %}