Claude Code routes some traffic through an internal agent-proxy, and that proxy needs its network certificate (a credential that lets other software verify it's talking to the real proxy) trusted by the operating system, Java, and NSS (the certificate library used by tools like Firefox). The installers that set up this trust were reworked so they can now handle a second certificate alongside the first, rather than assuming there is only ever one.
- The Java trust-store installer (which uses
keytool) and the NSS trust-store installer (which usescertutil) now detect and import a second CA certificate. - If seeding the Java trust store with
keytoolfails, it now retries once after a pause instead of giving up immediately. - The installers now record whether they found an 'old_layout' store, meaning one that still only holds a single certificate.
This lets Claude Code rotate to a new certificate for the agent-proxy without users suddenly losing trust in it, since both the old and new certificates can be recognized during the transition. The added retry on keytool seeding also makes the Java trust-store setup less likely to fail on a transient error.
The finding only names one seeding-failure event as evidence; it doesn't confirm how the retry or second-certificate detection behave beyond…