{"version":"2.1.288","anchor":"signed-cache-cert-check-reports-hours-left-instead-of-days","canonical_anchor":"signed-cache-cert-check-reports-hours-left-instead-of-days","heading":"Signed cache certificate check now trusts a single production issuer","tier":"internal","area":"Signed Cache","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/signed-cache-cert-check-reports-hours-left-instead-of-days","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Signed cache certificate check now trusts a single production issuer\n\nThe signed cache certificate check now trusts one named production issuer instead of a fixed list, and reports time left in hours\n\n**Unclear.** It is not clear whether verification behaves any differently for users.\n\n**What**\n\nClaude Code checks the certificates on its signed cache. A certificate is a digital credential that shows who issued something. Two things changed:\n\n- Trust: a fixed list of trusted root certificates is replaced by a single marker, `urn:anthropic:claude-code:signed-cache:production`, with the issuer named \"Claude Code Signed Cache Issuing CA\".\n\n- Reporting: the time a certificate has left before it expires is now reported in hours instead of days.\n\n**Why**\n\nThis changes how Claude Code decides which signed cache certificates to trust. Nothing here shows a visible difference for you.\n\n- Area: Signed Cache\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no"}