Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

Agent-proxy CA trust stores now support rotating to a second certificate

Claude Code's agent-proxy can now roll over to a second trusted certificate without breaking connections

Under the hood Improvements
JSON All of v2.1.280
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What

Claude Code routes some traffic through an internal agent-proxy, and that proxy needs its network certificate (a credential that lets other software verify it's talking to the real proxy) trusted by the operating system, Java, and NSS (the certificate library used by tools like Firefox). The installers that set up this trust were reworked so they can now handle a second certificate alongside the first, rather than assuming there is only ever one.

  • The Java trust-store installer (which uses keytool) and the NSS trust-store installer (which uses certutil) now detect and import a second CA certificate.
  • If seeding the Java trust store with keytool fails, it now retries once after a pause instead of giving up immediately.
  • The installers now record whether they found an 'old_layout' store, meaning one that still only holds a single certificate.
Why

This lets Claude Code rotate to a new certificate for the agent-proxy without users suddenly losing trust in it, since both the old and new certificates can be recognized during the transition. The added retry on keytool seeding also makes the Java trust-store setup less likely to fail on a transient error.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding only names one seeding-failure event as evidence; it doesn't confirm how the retry or second-certificate detection behave beyond…

See this entry in the whole of v2.1.280 →

Feedback