certutil -syncWithWU
To avoid this issue in the future:
This error manifests due to two primary industrial infrastructure conditions:
: The primary solution recommended by PTC is to apply all pending Windows Updates, which naturally refreshes the root certificate store.
During the installation process, the setup wrapper triggers a validation check against the operating system's local certificate store to verify that the installer is authentic and has not been tampered with.
Resolving Kepware Error: "The Installer Was Unable to Find Required Root Certificates"
To resolve this issue, you must ensure the system can trust the certificates used by the Kepware installer.
Right-click the certificate file and select . Choose Local Machine as the store location .
There are two primary methods to resolve this issue, ranging from the automated approach (recommended) to the manual approach (for strictly offline systems).
Troubleshooting "Kepware: The installer was unable to find required root certificates" Error
[Installer Execution] │ ▼ [Trigger Windows CryptoAPI] │ ▼ [Scan Local Certificate Store] ────► Missing GlobalSign/VeriSign Root CAs? │ │ │ (Validated Successfully) ▼ (Validation Fails) ▼ [Throw Error & Rollback] [Installation Proceeds] "The installer was unable to find required root certificates..."
: If the machine is offline, you must manually install the required root certificates (such as those from GlobalSign or VeriSign ).
Block the installer from reaching certificate validation endpoints:
Once the system is fully updated, restart your computer and try the Kepware installation again. Method 2: Manual Certificate Import (For Offline Machines)
: Group policies (GPOs) inside strict industrial networks often completely disable automatic root certificate updates. How to Resolve the Root Certificate Error Method 1: Apply Windows Updates (Recommended)
Windows cannot perform a "Root AutoUpdate" to fetch the latest certificates from Microsoft.