This should not harm us and it will reduce number of tickets to activate SSH.
In my test lxjailshell is not a true chroot environment. If you allowing vim or other editors they can break out easily. I have been securing a server that i paid to have audited. Perl was a nightmare. Lxjailshell is better off than on! You have to restrict it so much it makes it useless. And a true jail requires the commands to be copied to the /home of the user.
I have abandoned apache and proxies. I am moving forward with just hiawatha. I have setup individual jails using the cgi-wrapper in hiawatha, at the cost of 50 mb per customer. No real biggie.
Next is to change php session directory to /home/{user}/sessions - that was another security concern from my audit (shared hosting)
I can jailshell bash, but, again, all files must be copied to a users directory.
But, i am a security freak, and paranoid.