# User not authorized to perform USE in reservation VNETs only

**URL:** <https://forum.opennebula.io/t/user-not-authorized-to-perform-use-in-reservation-vnets-only/1270>\
**Category:** Product Support\
**Created:** [October 1, 2015, 1:09pm UTC](https://forum.opennebula.io/t/user-not-authorized-to-perform-use-in-reservation-vnets-only/1270 "2015-10-01T13:09:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hsanjuan](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/hsanjuan/32/4372_2.png) [@hsanjuan](https://forum.opennebula.io/u/hsanjuan)\
**Post date:** [October 1, 2015, 1:09pm UTC](https://forum.opennebula.io/t/user-not-authorized-to-perform-use-in-reservation-vnets-only/1270/1 "2015-10-01T13:09:57Z")

</div>

Hi, I am running OpenNebula 4.12.

I have a group of users “bots” (id 102).

Bots have an ACL that allows them to USE VirtualNetworks:

`13 @102 VHNI-T-DC---- * u--- *`

This works for regular virtual networks, they can run `vn.info!()` (using the Ruby OCA) and they get the VN information. However, when doing exactly the same with VirtualNetworks of type “Reservation”, I get

`[VirtualNetworkInfo] User [8] : Not authorized to perform USE NET [7].`

Am I missing something or might this be a bug? I’ve searched around without luck…

If I add a specific ACL specifing the ID of the VNET (7) instead of ALL, then it works :S

Thanks in advance…

---

<div class="post-metadata">

**Author:** ![hsanjuan](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/hsanjuan/32/4372_2.png) [@hsanjuan](https://forum.opennebula.io/u/hsanjuan)\
**Post date:** [October 13, 2015, 12:59pm UTC](https://forum.opennebula.io/t/user-not-authorized-to-perform-use-in-reservation-vnets-only/1270/2 "2015-10-13T12:59:58Z")

</div>

shameless bump 😄

---

<div class="post-metadata">

**Author:** ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)\
**Post date:** [October 13, 2015, 1:43pm UTC](https://forum.opennebula.io/t/user-not-authorized-to-perform-use-in-reservation-vnets-only/1270/3 "2015-10-13T13:43:14Z")

</div>

Hi

VNET reservations also includes an implicit ACL to by pass the ALL and cluster rules. This was introduced as a security requirement. For example, to not see reservation made by other users. Changes were made here:

[http://dev.opennebula.org/projects/opennebula/repository/revisions/acf5052009a045756e9b05d4331d1bc933f9fe53](http://dev.opennebula.org/projects/opennebula/repository/revisions/acf5052009a045756e9b05d4331d1bc933f9fe53)

I checked the docs, but could not see any references ☹ I’ll fill a ticket for this.

So in summary, this is the expected behavior.
