{"version":"2.1.282","anchor":"the-ccr-agent-proxy-skips-reinstalling-its-ca-when-the-nss-d","canonical_anchor":"the-ccr-agent-proxy-skips-reinstalling-its-ca-when-the-nss-d","heading":"Cloud containers stop reinstalling proxy certificates that are already trusted","tier":"notice","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/the-ccr-agent-proxy-skips-reinstalling-its-ca-when-the-nss-d","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Cloud containers stop reinstalling proxy certificates that are already trusted\n\nIn cloud sessions, Claude Code's proxy now leaves the certificate store alone when it already trusts the right certificates, not deleting and re-adding them\n\n**What**\n\nIn cloud sessions, Claude Code runs a proxy, a go-between for network traffic. The proxy has its own certificates, the files that let other programs trust its connections. It installs them into an NSS database, a certificate store that programs such as browsers use on Linux.\n\nIt used to delete the `ccr-agent-proxy` and `ccr-agent-proxy-2` certificates and add them again every time. Now it first lists what the database holds. If exactly the certificates it serves are already there and trusted, it leaves the database as it is.\n\n**Why**\n\nThis cuts needless rewriting of the certificate store in remote containers. It also avoids a short gap during which the certificate is missing from the store.\n\n- Area: Cloud Sessions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}