0
0 Items Selected

No products in the cart.

Kepware The Installer Was Unable: To Find Required Root Certificates Exclusive _top_

: For systems without internet access, you must manually install the required root certificates into the Trusted Root Certification Authorities

Why would such a root certificate be absent on a functional Windows machine? The answer lies in the evolution of operating systems and the fragmentation of industrial PC environments. Many factory-floor PCs run on legacy versions of Windows (7, Embedded Standard, or early Windows 10 builds) that have outdated or manually curated root certificate stores. Unlike consumer PCs that receive automatic updates via Windows Update, industrial PCs are often air-gapped or locked down to maintain stability, meaning they never receive the automatic root certificate updates released monthly by Microsoft. Consequently, when a newer Kepware installer—built and signed using a CA that came into prominence after the OS’s last update—runs on such a machine, the OS’s root store has no record of that CA. The installer queries the system, receives a “not found” response, and halts with the cryptic root certificate error.

If the server must remain offline, you must manually install the required certificates: Identify the certificate: The installer usually requires roots from GlobalSign Use MMC to import: Microsoft Management Console Certificates snap-in for the Local Computer Navigate to Trusted Root Certification Authorities Certificates Right-click, select , and point to the www.ptc.com 3. Use Certutil (Command Line)

If Windows Update is not an option, follow these steps to manually update your certificate store: Identify Missing Certificates : Common required root certificates include those from GlobalSign . Specific critical roots often include: GlobalSign Root CA - R3 DigiCert Trusted Root G4 Microsoft Code Verification Root Import via MMC , and press Enter. File > Add/Remove Snap-in Certificates Computer account (Local Computer). Navigate to Trusted Root Certification Authorities > Certificates Right-click, select All Tasks > Import , and browse to your downloaded certificate file. Ensure Correct Storage : For systems without internet access, you must

By following the methods in this guide—especially the for air-gapped networks—you can bypass this roadblock in minutes.

Only do this if you are confident in your environment's security. Re-enable it after installation. 4. Bypass Certificate Validation (Use Caution)

Right-click the certificate file and select . Choose Local Machine as the store location. Select Place all certificates in the following store . Browse and select Trusted Root Certification Authorities . Click Finish to complete the import. Step 2: Run Windows Update Unlike consumer PCs that receive automatic updates via

Solving "The Installer Was Unable to Find Required Root Certificates" in Kepware

If any certificate in the chain is missing or untrusted, the installer aborts to prevent execution of potentially tampered software.

The "exclusive" part of the error can occur if the Windows automatic root certificate update feature tries to lock the store while Kepware is attempting to read it. If the server must remain offline, you must

: The most direct fix is to connect the machine to the internet and run Windows Update to automatically refresh the local Trusted Root Certification Authorities store.

The safest and most reliable way to fix root certificate issues is to update the operating system.