# Behavior of masterkey on rSeries

**URL:** <https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676>\
**Category:** Technical Forums\
**Tags:** rseries, migration\
**Created:** [November 14, 2025, 11:11am UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676 "2025-11-14T11:11:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Klotz](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/stefan_klotz/32/19800_2.png) [@Stefan\_Klotz](https://community.f5.com/u/Stefan_Klotz)\
**Post date:** [November 14, 2025, 11:11am UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676/1 "2025-11-14T11:11:55Z")

</div>

Is there any difference in regards to the usage of the masterkey on rSeries?  
I mean is this still different/dedicated for the F5OS and all the tenants? Or is there just ONE masterkey, which needs to be adjusted on F5OS level?  
Reason why I’m asking, I want to load a bigip.conf file from an iSeries on a Tenant of a rSeries. I performed the procedure with f5mku commands to have the same masterkey on the new rSeries Tenant and it will also be displayed correctly.  
But when I try to load/verify the configuration (load sys config partition { xyz } verify) I still get the error message:

> Decryption of the field (pvalue) for object (xxx 1 PASSWORD=) failed while loading configuration that is encrypted with a different master key.

Is there anything else I should double check?  
Thank you!

Regards,  
Stefan 🙂

---

<div class="post-metadata">

**Author:** ![Jeff\_Granieri](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/jeff_granieri/32/8038_2.png) [@Jeff\_Granieri](https://community.f5.com/u/Jeff_Granieri)\
**Post date:** [November 14, 2025, 2:52pm UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676/2 "2025-11-14T14:52:27Z")

</div>

Hi @Stefan_Klotz &nbsp; &nbsp;Have you checked this K article [https://my.f5.com/manage/s/article/K000152642](https://my.f5.com/manage/s/article/K000152642)&nbsp; sometimes password’s/secrets used within the config aren’t encrypted properly with the current master key.&nbsp; You may need to adjust the config/BigDB.dat file.&nbsp; Worth a try.

---

<div class="post-metadata">

**Author:** ![Stefan\_Klotz](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/stefan_klotz/32/19800_2.png) [@Stefan\_Klotz](https://community.f5.com/u/Stefan_Klotz)\
**Post date:** [November 14, 2025, 4:40pm UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676/3 "2025-11-14T16:40:59Z")

</div>

Dear Jeffrey,  
thank you for the quick answer!  
My BigDB.dat file doesn’t contain an encrypted value in the section [Configsync.password] at all, so I don’t followed they other steps.  
I then realized that on the second tenant of the HA-cluster the load sys config command works fine without any issues.  
And finally the root cause on the primary tenant was somehow related to a time sync problem. I noticed that NTP was not working correctly due to wrong/mistyped NTP-servers (DNS-names).  
Once corrected the load sys config command was working fine on this tenant as well. Do you maybe have an explanation for this behavior?

Finally we can summarize: there is NO special behavior for the masterkey on rSeries. As already mentioned in [this F5 article](https://my.f5.com/manage/s/article/K000152853) replacing the masterkey with the f5mku command is sufficient.

Thank you anyway!

Regards,  
Stefan

---

<div class="post-metadata">

**Author:** ![Jeff\_Granieri](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/jeff_granieri/32/8038_2.png) [@Jeff\_Granieri](https://community.f5.com/u/Jeff_Granieri)\
**Post date:** [November 14, 2025, 8:38pm UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676/4 "2025-11-14T20:38:00Z")

</div>

I don’t have an explanation, but I do know NTP out of sync can cause all sorts of issues!

---

<div class="post-metadata">

**Author:** ![Stefan\_Klotz](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/stefan_klotz/32/19800_2.png) [@Stefan\_Klotz](https://community.f5.com/u/Stefan_Klotz)\
**Post date:** [February 2, 2026, 3:35pm UTC](https://community.f5.com/t/behavior-of-masterkey-on-rseries/76676/5 "2026-02-02T15:35:22Z")

</div>

I noticed that the default masterkey of all tenants within the same rSeries appliance is identical, which sounds like it is somehow inherit from the F5OS???  
I double checked the F5OS, but there the command f5mku is not valid.  
So is my assumption correct and if yes, can I change the masterkey directly on F5OS-level?  
Or is this totally independent and has nothing to do with F5OS?  
Thank you!

Regards,  
Stefan
