{"version":"2.1.288","anchor":"agent-proxy-ca-watch-rebuilds-system-and-tool-trust-and-retr","canonical_anchor":"agent-proxy-ca-watch-rebuilds-system-and-tool-trust-and-retr","heading":"Changed security certificates are reinstalled and retried automatically","tier":"notice","area":"Sessions","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/agent-proxy-ca-watch-rebuilds-system-and-tool-trust-and-retr","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Changed security certificates are reinstalled and retried automatically\n\nClaude Code now watches for a changed security certificate, updates the system and tool trust stores, and retries installs that do not take\n\n**Unclear.** It is not clear whether some of this certificate handling already existed in an earlier form.\n\n**What**\n\nClaude Code now watches for changes to a security certificate supplied to it, called a CA certificate, which other programs use to decide which connections to trust. When the certificate changes, Claude Code rewrites its certificate file. It then updates the trust stores, meaning the lists of trusted certificates kept by the operating system and by tools such as Java.\n\nIf a trust store does not accept the new certificate, Claude Code retries a limited number of times. After that it logs a warning and stops trying until the certificate changes again.\n\n**Why**\n\nThis makes certificate changes more reliable in managed or remote sessions, so connections keep working after a certificate is replaced.\n\n- Area: Sessions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: org\n- Heads-up: no"}