I happened to be behind a pretty restrictive firewall today, which allowed outbound access on ports 80/tcp and 443/tcp but not much else. This means U could not access the https://openstack.eqiad1.wikimediacloud.org:25000/ Keystone endpoint required to log in to Horizon via IDP. Could the Keystone endpoint use the standard HTTPS port 443 (on a different host name like keystone.openstack.eqiad1.wikimediacloud.org perhaps) please?
edited to add: let's do this for all openstack services