    I attempted to secure my VPS by following the info at this link:

    But I've run into some issues. Openbasedir was one I just posted about.

    Another is disabling password authentication and using Putty for ssh. When I do that, the support group can not access my vps to support it.

    Any ideas on how to disable password auth yet still allow support in?
    This is kind of like asking how to open your car door after you've welded it shut. Support uses password authentication, therefore, disabling it disables their ability to authenticate.
    I see you think outside the box. I was thinking we should be able to tie password authentication to an ip address that might be supports. I know they are in India but I don't know if it is a single IP address.
    Is this true?? Wow I've been running key auth for a while now and figured that support had their own ways to get in.

    That is a serious blow to security if we can't disable passworth auth...
    It almost certainly is not a single IP, and I'm not too sure KH support is in India.
    Well they are definitely in India as that is where the access logged them from. But I did not save past accessess so don't know if there are a few ip addressess that we bound to password login or not.
    We employ wide range of people located around the world, some of the company employees live and work in India, US as well as other countries.


