diff --git a/ansible/roles/keystone/templates/keystone.json.j2 b/ansible/roles/keystone/templates/keystone.json.j2
index 5d0486ede0ae4a9cae2ae856fc58d0000c2af21a..4269d7e0fa4ef755755547aec5e1b18110a22181 100644
--- a/ansible/roles/keystone/templates/keystone.json.j2
+++ b/ansible/roles/keystone/templates/keystone.json.j2
@@ -20,7 +20,7 @@
             "source": "{{ container_config_directory }}/domains",
             "dest": "/etc/keystone/domains",
             "owner": "keystone",
-            "perm": "0700",
+            "perm": "0600",
             "optional": true
         }{% if keystone_policy_file is defined %},
         {
@@ -49,6 +49,11 @@
             "path": "/etc/keystone/fernet-keys",
             "owner": "keystone:keystone",
             "perm": "0770"
+        },
+        {
+            "path": "/etc/keystone/domains",
+            "owner": "keystone:keystone",
+            "perm": "0700"
         }
     ]
 }