Eu consertei o problema, fazendo o hash identity_uri assim:
[keystone_authtoken]
auth_host = controller
auth_port = 35357
auth_protocol = http
auth_uri = http://controller:5000/v2.0
#identity_uri = http://controller:35357
admin_tenant_name = service
admin_user = nova
admin_password = openstack