Kepware The Installer Was Unable To Find Required Root Certificates Exclusive
You can also check the installation logs. Navigate to the bootstrap.log file located in C:\Program Files (x86)\Kepware\KEPServerEX\ or C:\Program Files (x86)\PTC\ThingWorxindustrialConnectivity\ . If the issue is resolved, the new log entries will no longer show the tell-tale error codes like -2146893807 (which indicates CERT_E_UNTRUSTEDROOT ), 0x65B , or entries like GlobalSign Failed .
The error "The installer was unable to find required root certificates exclusive" is a security check failure. It is resolved by ensuring the Windows Operating System trusts the digital signature of the Kepware installer. In most cases, running resolves the issue immediately. For air-gapped systems, manually importing the root certificate from a trusted USB source is the standard industrial solution.
Identify the missing certificate (e.g., GlobalSign or Microsoft) from the bootstrap.log file located in the Kepware installation directory. You can also check the installation logs
Critically, the installer does not download missing certificates automatically if the machine is offline or if Windows Update is disabled. This is a security feature—preventing automatic installation of untrusted certificates—but it becomes a roadblock for legitimate software.
Kepware's KEPServerEX is widely considered the industry standard for industrial connectivity, though its installation process can be sensitive to modern security standards on older or air-gapped systems. The error "The installer was unable to find
Solve the certificate problem, and you’ll be back to connecting your industrial devices in no time.
Delete the corrupted certificate store cache: For air-gapped systems
The word "exclusive" in the error message refers to the or a specific cryptographic context where the installer requires exclusive access to certificate validation resources. It implies that the installer attempted to build a certificate chain for validation but found that required root CAs were either:
To resolve this, you must ensure the host machine trusts the certificates used by PTC Kepware.
There are several primary causes:
: For systems without internet access, you must manually install the required root certificates into the Trusted Root Certification Authorities
