It's not that I don't just not trust the reseller, I don't trust *anyone* unknown with root credentials.
In these kind of situations I would expect a request for logs. Or to run package 'xzzz' and provide its feedback.
I don't expect a support issue to be treated as 'let us in, we'll have a...