PowerProtect Cyber Recovery: Vault in Degraded status with Alert Possible malicious behavior has been detected
Summary: Cyber Recovery in Degraded status with Alert Possible malicious behavior has been detected.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Cyber Recovery dashboard shows status as Degraded.
All sync-copy jobs have failed.
In the Cyber Recovery UI > Infrastructure > Assets > Vault Storage, attempting to edit the Data Domain asset and reenter the user password generates an alert when saving:
The mgmtdds.log (located by default in /opt/dellemc/cr/var/log/mgmtdds/) contains the following information:
All sync-copy jobs have failed.
In the Cyber Recovery UI > Infrastructure > Assets > Vault Storage, attempting to edit the Data Domain asset and reenter the user password generates an alert when saving:
The mgmtdds.log (located by default in /opt/dellemc/cr/var/log/mgmtdds/) contains the following information:
[2023-08-03 03:30:57.658] [INFO] [mgmtdds] [ddssh.go:692 CreateSSHClientConn()] :
Establish SSH connection using ssh-key with credential
[2023-08-03 03:30:57.658] [INFO] [mgmtdds] [ddssh.go:719 CreateSSHClientConn()] :
SSH connecting to dd.vault.local:22
[2023-08-03 03:30:57.731] [DEBUG] [mgmtdds] [sshkeys.go:320 getHostFingerprint()] :
Entering
[2023-08-03 03:30:58.145] [DEBUG] [mgmtdds] [sshkeys.go:397 getHostFingerprint()] :
fingerprint: 40:CF:9D:61:97:35:F6:DF:43:8F:DE:27:2F:E5:48:B8:05:9E:B5:31
[2023-08-03 03:30:58.145] [DEBUG] [mgmtdds] [sshkeys.go:398 getHostFingerprint()] :
Exiting
[2023-08-03 03:30:58.145] [ERROR] [mgmtdds] [ddssh.go:757 CreateSSHClientConn()] :
*** Alert *** Possible malicious behavior has been detected for host: dd.vault.localCause
When Cyber Recovery makes an SSH connection to Data Domain, it finds the fingerprint of the host has changed and issues a "malicious behavior" alert.
Resolution
Perform the following steps to resolve the issue:
Contact DELL Technical Support for any further information.
- Log in to Cyber Recovery UI as the crso user.
- Navigate to Infrastructure > Assets > Vault Storage.
- Select the vault Data Domain and click Edit.
- Enter the password for the user and then select the option for Reset Host Fingerprint.
- Click Save.
Contact DELL Technical Support for any further information.
Affected Products
PowerProtect Cyber RecoveryArticle Properties
Article Number: 000216438
Article Type: Solution
Last Modified: 26 May 2026
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.