hi.
After vault unsealed, juju status is all green:
juju status
Model      Controller       Cloud/Region    Version  SLA          Timestamp
openstack  maas-controller  mymaas/default  2.8.7    unsupported  07:55:00+08:00
App                     Version  Status  Scale  Charm                   Store  Rev  OS      Notes
ceph-mon                15.2.7   active      3  ceph-mon                local    0  ubuntu
ceph-osd                15.2.7   active      3  ceph-osd                local   15  ubuntu
ceph-radosgw            15.2.7   active      1  ceph-radosgw            local   26  ubuntu
cinder                  16.2.1   active      1  cinder                  local  136  ubuntu
cinder-ceph             16.2.1   active      1  cinder-ceph             local    2  ubuntu
cinder-mysql-router     8.0.23   active      1  mysql-router            local    0  ubuntu
dashboard-mysql-router  8.0.23   active      1  mysql-router            local    0  ubuntu
glance                  20.0.1   active      1  glance                  local  150  ubuntu
glance-mysql-router     8.0.23   active      1  mysql-router            local    0  ubuntu
keystone                17.0.0   active      1  keystone                local    0  ubuntu
keystone-mysql-router   8.0.23   active      1  mysql-router            local    0  ubuntu
mysql-innodb-cluster    8.0.23   active      3  mysql-innodb-cluster    local    0  ubuntu
neutron-api             16.2.0   active      1  neutron-api             local    0  ubuntu
neutron-api-plugin-ovn  16.2.0   active      1  neutron-api-plugin-ovn  local    0  ubuntu
neutron-mysql-router    8.0.23   active      1  mysql-router            local    0  ubuntu
nova-cloud-controller   21.1.0   active      1  nova-cloud-controller   local  501  ubuntu
nova-compute            21.1.0   active      3  nova-compute            local  133  ubuntu
nova-mysql-router       8.0.23   active      1  mysql-router            local    0  ubuntu
ntp                     3.5      active      3  ntp                     local    0  ubuntu
openstack-dashboard     18.3.2   active      1  openstack-dashboard     local   32  ubuntu
ovn-central             20.03.1  active      3  ovn-central             local    0  ubuntu
ovn-chassis             20.03.1  active      3  ovn-chassis             local    0  ubuntu
placement               3.0.0    active      1  placement               local    0  ubuntu
placement-mysql-router  8.0.23   active      1  mysql-router            local    0  ubuntu
rabbitmq-server         3.8.2    active      3  rabbitmq-server         local  150  ubuntu
vault                   1.5.4    active      1  vault                   local    0  ubuntu
vault-mysql-router      8.0.23   active      1  mysql-router            local    0  ubuntu
Unit                         Workload  Agent  Machine   Public address  Ports              Message
ceph-mon/0                   active    idle   0/lxd/6   10.0.2.68                          Unit is ready and clustered
ceph-mon/1                   active    idle   1/lxd/6   10.0.2.92                          Unit is ready and clustered
ceph-mon/2*                  active    idle   2/lxd/4   10.0.2.59                          Unit is ready and clustered
ceph-osd/0                   active    idle   0         10.0.0.159                         Unit is ready (1 OSD)
ceph-osd/1                   active    idle   1         10.0.0.156                         Unit is ready (1 OSD)
ceph-osd/2*                  active    idle   2         10.0.0.157                         Unit is ready (1 OSD)
ceph-radosgw/0*              active    idle   0/lxd/7   10.0.2.72       80/tcp             Unit is ready
cinder/0*                    active    idle   1/lxd/7   10.0.2.87       8776/tcp           Unit is ready
  cinder-ceph/0*             active    idle             10.0.2.87                          Unit is ready
  cinder-mysql-router/0*     active    idle             10.0.2.87                          Unit is ready
glance/0*                    active    idle   2/lxd/5   10.0.2.60       9292/tcp           Unit is ready
  glance-mysql-router/0*     active    idle             10.0.2.60                          Unit is ready
keystone/0*                  active    idle   0/lxd/8   10.0.2.81       5000/tcp           Unit is ready
  keystone-mysql-router/0*   active    idle             10.0.2.81                          Unit is ready
mysql-innodb-cluster/0       active    idle   0/lxd/9   10.0.2.75                          Unit is ready: Mode: R/O
mysql-innodb-cluster/1       active    idle   1/lxd/8   10.0.2.83                          Unit is ready: Mode: R/O
mysql-innodb-cluster/2*      active    idle   2/lxd/6   10.0.2.58                          Unit is ready: Mode: R/W
neutron-api/0*               active    idle   1/lxd/9   10.0.2.84       9696/tcp           Unit is ready
  neutron-api-plugin-ovn/0*  active    idle             10.0.2.84                          Unit is ready
  neutron-mysql-router/0*    active    idle             10.0.2.84                          Unit is ready
nova-cloud-controller/0*     active    idle   0/lxd/10  10.0.2.76       8774/tcp,8775/tcp  Unit is ready
  nova-mysql-router/0*       active    idle             10.0.2.76                          Unit is ready
nova-compute/0               active    idle   0         10.0.0.159                         Unit is ready
  ntp/1                      active    idle             10.0.0.159      123/udp            chrony: Ready
  ovn-chassis/1              active    idle             10.0.0.159                         Unit is ready
nova-compute/1               active    idle   1         10.0.0.156                         Unit is ready
  ntp/2                      active    idle             10.0.0.156      123/udp            chrony: Ready
  ovn-chassis/2              active    idle             10.0.0.156                         Unit is ready
nova-compute/2*              active    idle   2         10.0.0.157                         Unit is ready
  ntp/0*                     active    idle             10.0.0.157      123/udp            chrony: Ready
  ovn-chassis/0*             active    idle             10.0.0.157                         Unit is ready
openstack-dashboard/0*       active    idle   1/lxd/10  10.0.2.90       80/tcp,443/tcp     Unit is ready
  dashboard-mysql-router/0*  active    idle             10.0.2.90                          Unit is ready
ovn-central/0                active    idle   0/lxd/11  10.0.2.74       6641/tcp,6642/tcp  Unit is ready
ovn-central/1                active    idle   1/lxd/11  10.0.2.82       6641/tcp,6642/tcp  Unit is ready
ovn-central/2*               active    idle   2/lxd/7   10.0.2.62       6641/tcp,6642/tcp  Unit is ready (leader: ovnnb_db, ovnsb_db northd: active)
placement/0*                 active    idle   2/lxd/8   10.0.2.66       8778/tcp           Unit is ready
  placement-mysql-router/0*  active    idle             10.0.2.66                          Unit is ready
rabbitmq-server/0            active    idle   0/lxd/12  10.0.2.79       5672/tcp           Unit is ready and clustered
rabbitmq-server/1            active    idle   1/lxd/12  10.0.2.93       5672/tcp           Unit is ready and clustered
rabbitmq-server/2*           active    idle   2/lxd/9   10.0.2.65       5672/tcp           Unit is ready and clustered
vault/0*                     active    idle   0/lxd/13  10.0.2.78       8200/tcp           Unit is ready (active: true, mlock: disabled)
  vault-mysql-router/0*      active    idle             10.0.2.78                          Unit is ready
Machine   State    DNS         Inst id               Series  AZ       Message
0         started  10.0.0.159  node4                 focal   default  Deployed
0/lxd/0   started  10.0.2.71   juju-33d214-0-lxd-0   focal   default  Container started
0/lxd/1   started  10.0.2.77   juju-33d214-0-lxd-1   focal   default  Container started
0/lxd/2   started  10.0.2.69   juju-33d214-0-lxd-2   focal   default  Container started
0/lxd/3   started  10.0.2.73   juju-33d214-0-lxd-3   focal   default  Container started
0/lxd/4   started  10.0.2.80   juju-33d214-0-lxd-4   focal   default  Container started
0/lxd/5   started  10.0.2.70   juju-33d214-0-lxd-5   focal   default  Container started
0/lxd/6   started  10.0.2.68   juju-33d214-0-lxd-6   focal   default  Container started
0/lxd/7   started  10.0.2.72   juju-33d214-0-lxd-7   focal   default  Container started
0/lxd/8   started  10.0.2.81   juju-33d214-0-lxd-8   focal   default  Container started
0/lxd/9   started  10.0.2.75   juju-33d214-0-lxd-9   focal   default  Container started
0/lxd/10  started  10.0.2.76   juju-33d214-0-lxd-10  focal   default  Container started
0/lxd/11  started  10.0.2.74   juju-33d214-0-lxd-11  focal   default  Container started
0/lxd/12  started  10.0.2.79   juju-33d214-0-lxd-12  focal   default  Container started
0/lxd/13  started  10.0.2.78   juju-33d214-0-lxd-13  focal   default  Container started
1         started  10.0.0.156  node2                 focal   default  Deployed
1/lxd/0   started  10.0.2.94   juju-33d214-1-lxd-0   focal   default  Container started
1/lxd/1   started  10.0.2.89   juju-33d214-1-lxd-1   focal   default  Container started
1/lxd/2   started  10.0.2.88   juju-33d214-1-lxd-2   focal   default  Container started
1/lxd/3   started  10.0.2.85   juju-33d214-1-lxd-3   focal   default  Container started
1/lxd/4   started  10.0.2.86   juju-33d214-1-lxd-4   focal   default  Container started
1/lxd/5   started  10.0.2.91   juju-33d214-1-lxd-5   focal   default  Container started
1/lxd/6   started  10.0.2.92   juju-33d214-1-lxd-6   focal   default  Container started
1/lxd/7   started  10.0.2.87   juju-33d214-1-lxd-7   focal   default  Container started
1/lxd/8   started  10.0.2.83   juju-33d214-1-lxd-8   focal   default  Container started
1/lxd/9   started  10.0.2.84   juju-33d214-1-lxd-9   focal   default  Container started
1/lxd/10  started  10.0.2.90   juju-33d214-1-lxd-10  focal   default  Container started
1/lxd/11  started  10.0.2.82   juju-33d214-1-lxd-11  focal   default  Container started
1/lxd/12  started  10.0.2.93   juju-33d214-1-lxd-12  focal   default  Container started
2         started  10.0.0.157  node1                 focal   default  Deployed
2/lxd/0   started  10.0.2.63   juju-33d214-2-lxd-0   focal   default  Container started
2/lxd/1   started  10.0.2.67   juju-33d214-2-lxd-1   focal   default  Container started
2/lxd/2   started  10.0.2.61   juju-33d214-2-lxd-2   focal   default  Container started
2/lxd/3   started  10.0.2.64   juju-33d214-2-lxd-3   focal   default  Container started
2/lxd/4   started  10.0.2.59   juju-33d214-2-lxd-4   focal   default  Container started
2/lxd/5   started  10.0.2.60   juju-33d214-2-lxd-5   focal   default  Container started
2/lxd/6   started  10.0.2.58   juju-33d214-2-lxd-6   focal   default  Container started
2/lxd/7   started  10.0.2.62   juju-33d214-2-lxd-7   focal   default  Container started
2/lxd/8   started  10.0.2.66   juju-33d214-2-lxd-8   focal   default  Container started
2/lxd/9   started  10.0.2.65   juju-33d214-2-lxd-9   focal   default  Container started
then config openstack :
source openrcv3_project
echo $OS_USERNAME
admin
openstack endpoint list --interface admin
Failed to discover available identity versions when contacting https://10.0.2.81:5000/v3. Attempting to parse version from URL.
SSL exception connecting to https://10.0.2.81:5000/v3/auth/tokens: HTTPSConnectionPool(host=‘10.0.2.81’, port=5000): Max retries exceeded with url: /v3/auth/tokens (Caused by SSLError(SSLError(“bad handshake: Error([(‘SSL routines’, ‘tls_process_server_certificate’, ‘certificate verify failed’)],)”,),))
source openrc
openstack endpoint list --interface admin
Could not find a suitable TLS CA certificate bundle, invalid path: /tmp/root-ca.crt
Do I need Managing TLS certificates in next step?
thank you a lot!