Without having a cookie key set, after the upgrade, clients will still be able to log in.
But the key should be set for security.
This can be fixed without losing passwords by old customers.
Old customers will log in using an empty cookie key, but after logging in, their password will be re-encrypted using the new cookie key.
To introduce such change, you have to commission it to a programmer.