{"version":"2.1.288","anchor":"certificate-chain-validation-tightened-basicconstraints-pat","canonical_anchor":"certificate-chain-validation-tightened-basicconstraints-pat","heading":"Device attestation rejects more kinds of faulty certificate chains","tier":"notice","area":"Device Attestation","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/certificate-chain-validation-tightened-basicconstraints-pat","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Device attestation rejects more kinds of faulty certificate chains\n\nDevice attestation now rejects certificate chains that run too long, end in an authority certificate, or name the wrong issuer\n\n**Unclear.** Where in Claude Code this check is used is not stated.\n\n**What**\n\nA certificate chain is a series of digital certificates that vouch for a device, each one signed by the one above it. When Claude Code checks a device's attestation, it now reads the limits written into each certificate. It refuses the chain as bad when any of these is true:\n\n- the chain is longer than one of its certificates allows\n\n- the last certificate, the one for the device itself, is marked as a certificate authority, meaning a certificate allowed to sign others\n\n- the issuer's name does not match\n\nBefore, only expiry dates and a marker were checked.\n\n**Why**\n\nChains that used to pass may now be rejected.\n\n- Area: Device Attestation\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5\n- Scope: org\n- Heads-up: no"}