| Previous | Next |
| DNS_ERROR_TOO_MANY_SKDS | DNS_ERROR_INVALID_INITIAL_ROLLOVER_OFFSET |
DNS_ERROR_INVALID_ROLLOVER_PERIOD
DNS_ERROR_INVALID_ROLLOVER_PERIOD means the requested DNSSEC key rollover interval is outside the valid range or cannot be used with the current signing policy.
What to check
- Review the KSK or ZSK rollover interval together with signature validity and propagation timing.
- Use the zone signing settings to inspect the current schedule before applying a new one.
- Plan changes so that parent DS publication and resolver caches have time to converge during KSK rollovers.
Get-DnsServerDnsSecZoneSetting -ZoneName "example.com"
Microsoft: Sign DNS zones with DNSSEC
Microsoft: Get-DnsServerDnsSecZoneSetting
Microsoft: Test-DnsServerDnsSecZoneSetting
Looking for a different code? Search another status or error code.