Yeah, you really have to be careful about opening port 22 to the world. Since ssh/sftp/scp, etc run off of the same port, you really open up a hole that you don't want to mess with...
Can you use a webshare over https instead??? That's what we do in the Windows world. It authenticates using AD. You may be able to do the same thing using ldap....
__________________
Pimps and Ho's - it's this generation's cowboys and indians
|