* Remove _member_ role from the keystone accepted roles
* Haproxy: When using TLS everywhere, use verifyhost for the balancermembers
* Fill DNS name for haproxy certificates