Forum Discussion

mawan_335293's avatar
mawan_335293
Icon for Nimbostratus rankNimbostratus
Apr 11, 2018

reset - masterkey

i want to do a platform migrate - but the UCS file has encrypted passwords - and i dont know the source BIG-IP system master key password or passphrase -- so the option is - to reset it on the source and re- generate the UCS - reset the passphrase on the new platform to match the source and import the UCS

 

QUESTION -- does resetting the Master Key have any impact on any other config -- my concern is for the Source system - if i reset - is there a potential of any issue Thank s

 

  • Why do you wanna reset the master key when you get it by running simple commands,

    f5mku -K

    Run the above on your existing platform1, it will give you the master key. Note it down.

    On your new platform, use the re-key command

    f5mku -r 
    ,

    Then load the ucs file.

    tmsh load sys ucs .ucs no-license

    Refer this article, you'll have your answers.

  • Just do this, Simple and straight forward command iv'e used several time, to modify the master key

     

    tmsh modify /sys crypto master-key prompt-for-password

     

  • Just remember two things:

    Save config after master key re-generation

    tmsh modify /sys crypto master-key prompt-for-password
    tmsh save /sys config
    

    Check matching key on another units in HA cluster

    f5mku -K
    
  • How do we approach this same situation considering it was a standalone device (not ha) and the unit died?