---
name: hs-crypto-troubleshooting-master-key-rotation
title: Why do I fail to load the new master key during the master key rotation process?
description: After you run the `cryptounit-mk-rotate` command in the TKE CLI, you fail to load the new master key to the Current Master Key Register.
last-updated: 2026-07-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hs-crypto?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Why do I fail to load the new master key during the master key rotation process?
{: #troubleshoot-master-key-rotation}

IBM Cloud&reg; Hyper Protect Crypto Services is deprecated. As of 28 March 2026, you can't create new instances, and access to free instances will be removed. Existing premium plan instances are supported until 28 March 2027. Any instances that still exist on that date will be deleted.
{: deprecated}
{: troubleshoot}
{: support}

After you run the `cryptounit-mk-rotate` command in the TKE CLI, you fail to load the new master key to the Current Master Key Register.
{: shortdesc}

The new master key is not in `Valid` state in the current master key register after you run the `cryptounit-mk-rotate` command.
{: tsSymptoms}

You accidentally exit the TKE CLI window when the root keys are being rewrapped by the new master key after you run the `cryptounit-mk-rotate` command.
{: tsCauses}

Run the `cryptounit-mk-rotate` command again to resume the root key rewrap operations. When prompted, enter the password for the current signature key file to activate the new master key.
{: tsResolve}