# ACLs for Templates restricted to Groups. Need help understanding

**URL:** <https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801>\
**Category:** Product Support\
**Created:** [November 4, 2019, 6:34pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801 "2019-11-04T18:34:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![josephg](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@josephg](https://forum.opennebula.io/u/josephg)\
**Post date:** [November 4, 2019, 6:34pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/1 "2019-11-04T18:34:04Z")

</div>

Hi, what’s the best way to restrict users from seeing all Templates to just templates that their group has the correct permissions to use?

Currently, we are running Open Nebula 5.8.1.  
Permissions on Templates are set to what we think are appropriate. Owner, Group and not usually Other.

However, when a user logs in they see all templates that exist regardless of the Template permission. I’m wanting for a user in a group to only see templates that are group permitted to use.

I know I need to provide a bit more detail, so please let me know what would need to be known to get this working.

---

<div class="post-metadata">

**Author:** ![ahuertas](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ahuertas/32/7487_2.png) [@ahuertas](https://forum.opennebula.io/u/ahuertas)\
**Post date:** [November 5, 2019, 8:11am UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/2 "2019-11-05T08:11:32Z")

</div>

Hello @josephg

Having that permissions should be correct, but maybe you have some ACL rule which gives access to that templates to everyone. So please, check your ACL rules that applies to VM templates and delete those ones that you don’t need. To see more information about ACL you can check [this](http://docs.opennebula.org/5.8/operation/users_groups_management/chmod.html#managing-acl-rules).

---

<div class="post-metadata">

**Author:** ![josephg](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@josephg](https://forum.opennebula.io/u/josephg)\
**Post date:** [November 5, 2019, 3:30pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/3 "2019-11-05T15:30:19Z")

</div>

We’ve looked at that document before, but will re-review it. One thing we can’t seem to determine is how to edit an ACL. This does not seem possible. Is it possible?

---

<div class="post-metadata">

**Author:** ![josephg](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@josephg](https://forum.opennebula.io/u/josephg)\
**Post date:** [November 5, 2019, 3:34pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/4 "2019-11-05T15:34:48Z")

</div>

onegroup create ${group} --resources VM+TEMPLATE

Is the command we use which then uses the system default ACLs. I’m not seeing a way to pass restrictions there.

---

<div class="post-metadata">

**Author:** ![ahuertas](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ahuertas/32/7487_2.png) [@ahuertas](https://forum.opennebula.io/u/ahuertas)\
**Post date:** [November 6, 2019, 4:06pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/5 "2019-11-06T16:06:48Z")

</div>

Hello @josephg

No, you can’t update the ACL, you need to delete and create a new one.

With that command, you specify the resources that the group can create, if you want more restriction you need to use the ACL rules.

---

<div class="post-metadata">

**Author:** ![josephg](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@josephg](https://forum.opennebula.io/u/josephg)\
**Post date:** [November 7, 2019, 9:15pm UTC](https://forum.opennebula.io/t/acls-for-templates-restricted-to-groups-need-help-understanding/7801/6 "2019-11-07T21:15:06Z")

</div>

Thanks. Will give that a try.
