Forum Discussion

F5-Geek's avatar
F5-Geek
Icon for Nimbostratus rankNimbostratus
May 28, 2018

Replacing Masterkey

I am planning to replace the masterkey for one of our vcmp guests in DC to match with other DR for GTM sysnc

 

I know the process to replace the master key

 

I am worried about whether it will impact ldap servers, monitoring,paraphrase which uses master key for there encryption

 

4 Replies

  • When you change the master key, the system will take care of implications for that change. Use tmsh to change the master key, and save the configuration after.

     

    I don't remember to ever have to play with master keys because of GTM. Are you sure you are not facing this bug?

     

    https://support.f5.com/csp/article/K96156151

     

  • Hi,

     

    In fact if you change master key, you will have an problem with encrypt configuration object passwords or passphrases (ldap, monitor with pwd, sso profile with sso, ...). you can change these password once the master key is migrated but before go ahead why you need to do that for GTM, what is your initial problem?

     

    you can just bigip_add or gtm_add depending if it is a GTM or just LTM (not GTM):

     

    https://support.f5.com/csp/article/K13312

     

    Regards