About Kepware certificate being automatically added under OPC UA Client Certificate

Hello,

I have a question about OPC UA security (Client Security) in Ignition.Recently, I configured an OPC UA connection from Ignition to Kepware (KEPServerEX). After that, I checked the following page in the Gateway Web UI:Gateway > Config > OPC UA Security > Client Certificate
and noticed that a Kepware certificate had been added, even though I did not manually register it.

Could you please confirm whether my understanding is correct:
in OPC UA, in order to establish secure communication (Sign/Encrypt), the client and server exchange certificates during connection establishment, and the certificates are then placed into a trust/reject list where the user can decide whether to trust or reject them?

Also, how should I determine whether the certificate is an official / legitimate certificate (i.e., whether it is the correct certificate for that Kepware server)?

When you went through the "wizard" adding the connection, you marked it trusted at this point:

You can instead select No there and it should end up in the "quarantine" area for you to further verify if you'd like.