diff --git a/etc/kolla/globals.yml b/etc/kolla/globals.yml
index 2885061c44..ecf18983fb 100644
--- a/etc/kolla/globals.yml
+++ b/etc/kolla/globals.yml
@@ -174,8 +174,12 @@
 # To provide encryption and authentication on the kolla_external_vip_interface,
 # TLS can be enabled.  When TLS is enabled, certificates must be provided to
 # allow clients to perform authentication.
-#kolla_enable_tls_external: "no"
+#kolla_enable_tls_internal: "no"
+#kolla_enable_tls_external: "{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else 'no' }}"
 #kolla_external_fqdn_cert: "{{ node_config }}/certificates/haproxy.pem"
+#kolla_internal_fqdn_cert: "{{ node_config }}/certificates/haproxy-internal.pem"
+#kolla_external_fqdn_cacert: "{{ node_config }}/certificates/haproxy-ca.crt"
+#kolla_internal_fqdn_cacert: "{{ node_config }}/certificates/haproxy-ca-internal.crt"
 
 ################
 # Region options