TLS and certificate authentication
Connect securely and troubleshoot certificate problems without switching off verification.
On this page
TLS protects the connection between Textual and an IRC server. It does not, by itself, make channel messages end-to-end encrypted or prevent the network from processing them.
When a server certificate is rejected
Check the server hostname, your Mac's date and time, and the network's current secure port. A certificate for a different hostname, an expired certificate, or a missing intermediate certificate needs to be corrected by the appropriate party.
Do not turn off certificate-chain validation simply to make an error disappear. If the network intentionally uses a private certificate authority, obtain its verification instructions through a trusted channel before changing trust settings. A self-signed client certificate used for your own authentication is a different matter from an untrusted server certificate.
The old FAQ's blanket TLS 1.0 statement is not current security guidance: TLS 1.0 and 1.1 are deprecated. The negotiated protocol also depends on the client build, macOS and server configuration.
Identify with a client certificate
Textual can present a certificate from your keychain to an IRC network. In Server Properties → Advanced → Client Certificate, choose the certificate identity you intend to use, then save the connection.
Register the fingerprint using your network's documented procedure. Do not work through the old guide's SHA-256, SHA-1 and MD5 list until something happens to be accepted: networks have specific requirements. Libera's current CertFP guide specifies SHA-512 and explains the TLS requirement for SASL EXTERNAL.
The original Textual guide preserves the Keychain Access and selection screenshots, but its fingerprint instructions are historical. Keychain Access menus may differ across macOS versions.
Protect your certificate identity
A certificate identity includes a private key that can grant access to your IRC account. Keep it private, make an appropriate backup, and follow the network's revocation or replacement procedure if it is lost or exposed.
The documented Textual behavior is to attempt SASL EXTERNAL when a client certificate is configured. Avoid changing hidden preferences to disable that behavior unless you understand why the particular network or bouncer requires it.
Keep reading
Source material
Adapted from the Textual knowledgebase, with related historical details preserved in the legacy library.
Need a hand? Contact us about this guide.