What
Java programs keep the certificates they trust in a file called a truststore, and keytool is Java's command for managing it. When Claude Code imports a CA certificate (a certificate that vouches for other certificates, often a company's own) with keytool -importcert, it no longer adds the -trustcacerts option to that command.
Why
This changes how custom CA certificates end up in a Java truststore. If you rely on Claude Code to set up a custom certificate for Java tools, the import now runs with a different set of options than before.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
When Claude Code runs this import, and what practical difference dropping the option makes, is not established.