{"version":"2.1.285","anchor":"agent-proxy-ca-source-reconcile","canonical_anchor":"agent-proxy-ca-source-reconcile","heading":"Proxied cloud sessions change how they set up certificate trust","tier":"internal","area":"Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/agent-proxy-ca-source-reconcile","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Proxied cloud sessions change how they set up certificate trust\n\nThe agent proxy now logs where its certificate authority comes from and runs a reconcile step when it comes from the environment\n\n**Unclear.** When the certificate comes from the environment rather than being fetched is not clear.\n\n**What**\n\nIn cloud sessions that route traffic through the agent proxy, Claude Code needs a certificate authority (the certificate that lets it trust secure connections through the proxy). At startup it now logs where that certificate came from and records it in its usage data. When the certificate comes from the environment, it runs an extra step to reconcile it. The step that fetches the certificate no longer saves the certificate file itself; that now happens in the code that asked for it.\n\n**Why**\n\nThis changes how trust for secure connections is set up in proxied cloud sessions. If it fails, Claude Code logs \"[agent-proxy] CA reconcile crashed\".\n\n- Area: Sessions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 2\/5"}