Kepware The Installer Was Unable To Find Required Root Certificates Exclusive
Right-click and select Import .
Identify the missing certificate (often a or DigiCert root used for code signing).
You can download the "DigiCert Global Root CA" from the official DigiCert website. Install the certificate: Right-click and select Import
Click Browse, select , and click OK. Complete the wizard. Restart the Kepware Installer. 3. Disable Secure Boot (Temporary Workaround)
This error is a , not a bug. It ensures that Kepware components are properly signed and untampered. Attempting to bypass the check without updating the root store is strongly discouraged in production or regulated environments (NERC CIP, IEC 62443, FDA, etc.). Install the certificate: Click Browse, select , and
If the patch fails or the log points to a specific missing certificate, you can manually import it using the Microsoft Management Console (MMC).
If the target machine is allowed temporary internet access, the absolute fastest way to resolve the validation problem is to let Windows update its built-in database automatically. Open the and search for Check for updates . Click the Check for updates button. Install the certificate: Click Browse
If the target machine has internet access, updating Windows will refresh the certificate store automatically. Press Windows Key + I to open . Navigate to Update & Security > Windows Update . Click Check for updates . Install all critical and optional updates. Restart your computer and rerun the Kepware installer. Step 3: Enable Automatic Root Certificate Updates
An error return code of 0x65B explicitly confirms that the system's cryptographic functions cannot find a trusted certificate trail. Step-by-Step Solutions
Before running any Kepware installer, run this PowerShell script to check for common root certs:
: For systems without internet access, you must manually install the required root certificates into the Trusted Root Certification Authorities