Network error occurs in Exploratory Desktop with the "unable to get local issuer certificate" error

After installing Exploratory Desktop, you may not be able to connect to the network when logging in, and an error occurs. A key characteristic of this problem is that you can connect to exploratory.io without any problem in your web browser.

Problem

When you check the log file, the following error is recorded at login.

UNABLE_TO_GET_ISSUER_CERT_LOCALLY
Error: unable to get local issuer certificate
at TLSSocket.onConnectSecure

Cause

At startup, Exploratory Desktop loads the certificates in the Windows “Trusted Root Certification Authorities” store and uses them to verify the communication with the Exploratory servers. It does not refer to the “Intermediate Certification Authorities” store.

The Exploratory server certificate is issued by Let’s Encrypt, and its top-level root certificate is ISRG Root X1. If this certificate is not in the “Trusted Root Certification Authorities” store on the PC, the server certificate cannot be verified, which results in the error above.

Windows does not include some root certificates from the beginning. Instead, it downloads and adds them the first time an application needs them. On the other hand, Chrome and Edge verify certificates using their own list of root certificates instead of the Windows store. As a result, you can connect in a browser, but only Exploratory Desktop, which refers to the Windows store, fails.

This is especially likely to happen on PCs where automatic updates of root certificates are disabled by company policy.

Solution

1. Check the cause

On the PC where the problem occurs, run the following in PowerShell.

Get-ChildItem Cert:\LocalMachine\Root, Cert:\CurrentUser\Root | ? Subject -match 'ISRG' | select Subject, Thumbprint, NotAfter, PSParentPath

If CN=ISRG Root X1 is displayed only on the PC that works correctly, this problem is the cause.

2. Install ISRG Root X1

The certificate you need to add is as follows.

Item Details
Certificate name ISRG Root X1 (Issuer: Internet Security Research Group)
Type Root certificate (you do not need to add the intermediate certificates)
Install location “Trusted Root Certification Authorities” of the “Local Computer”

If you install it on the “Local Computer”, it is valid for all users of that PC.

  1. Download the certificate (isrgrootx1.der) from the following URL.
    https://letsencrypt.org/certs/isrgrootx1.der

  2. Verify that the downloaded file is the correct one using the following values.

    Item Value
    Thumbprint (SHA-1. Same value as “Thumbprint” in the PowerShell output above) CABD2A79A1076A31F21D253635CB039D4329A5E8
    SHA-256 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
    Expiration date June 4, 2035
  3. Double-click the file and click “Install Certificate”.

  4. For the store location, select “Local Machine”.

  5. Select “Place all certificates in the following store”, specify “Trusted Root Certification Authorities”, and complete the installation.

  6. Because certificates are loaded at startup, close Exploratory Desktop once and start it again. If it starts in online mode, the problem is resolved.

If you cannot freely add certificates to a company-issued PC, you can also export the certificate from a PC that works correctly and import it to the PC with the problem. In this case as well, please follow the instructions of your company’s IT department.

Note that “ISRG Root X2”, which is issued by the same organization, is not enough to verify the communication with download2.exploratory.io, where R packages are downloaded from. Please make sure to add “ISRG Root X1”.

3. If the problem is not resolved after adding ISRG Root X1

The contents of the communication may be inspected (HTTPS inspection) on your company network. In that case, you also need to add the company certificate used for the inspection to the “Trusted Root Certification Authorities” of the “Local Computer” in the same way.

Supplement: Connection destinations and ports

Exploratory Desktop connects to the following over HTTPS (port 443).

If you try the solutions above and the problem is still not resolved, please contact our support team (support@exploratory.io).