Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Device attestation rejects more kinds of faulty certificate chains

Device attestation now rejects certificate chains that run too long, end in an authority certificate, or name the wrong issuer

You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Device AttestationArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release
What

A certificate chain is a series of digital certificates that vouch for a device, each one signed by the one above it. When Claude Code checks a device's attestation, it now reads the limits written into each certificate. It refuses the chain as bad when any of these is true:

  • the chain is longer than one of its certificates allows
  • the last certificate, the one for the device itself, is marked as a certificate authority, meaning a certificate allowed to sign others
  • the issuer's name does not match

Before, only expiry dates and a marker were checked.

Why

Chains that used to pass may now be rejected.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhere in Claude Code this check is used is not stated.

See this entry in the whole of v2.1.288 →

Feedback