/msg NickServ SENDPASS youraccountnamehere
/msg NickServ SET PASSWORD newpasswordhere
If your account is compromised and you are unable to change or reset the password, please contact Libera.Chat staff in #libera or /stats p as soon as possible for assistance. You can also reach us at [email protected] if you would prefer to discuss over email.
Connecting to Libera.Chat
Libera.Chat can be accessed using an IRC client.
Connect to Libera.Chat with TLS at irc.libera.chat on port 6697.
Additional regional and address-specific hostnames are available:
Default irc.libera.chat
Europe irc.eu.libera.chat
US & Canada irc.us.libera.chat
Australia and New Zealand irc.au.libera.chat
East Asia irc.ea.libera.chat
IPv4 only irc.ipv4.libera.chat
IPv6 only irc.ipv6.libera.chat
Additional ports are available:
Plain-text 6665-6667, 8000-8002
TLS 6697, 7000, 7070
Accessing Libera.Chat Via TLS
Libera.Chat provides TLS client access on all servers, on ports 6697, 7000 and 7070. Users connecting over TLS will be given user mode +Z, and is using a secure connection will appear in WHOIS (a 671 numeric).
In order to verify the server certificates on connection, some additional work may be required. First, ensure that your system has an up-to-date set of root CA certificates. On most linux distributions this will be in a package named something like ca-certificates. Many systems install these by default, but some (such as FreeBSD) do not. For FreeBSD, the package is named ca_root_nss, which will install the appropriate root certificates in /usr/local/share/certs/ca-root-nss.crt.
Certificate verification will generally only work when connecting to libera.chat. If your client thinks the server’s certificate is invalid, make sure you are connecting to irc.libera.chat rather than any other name that leads to Libera.Chat.
For most clients this should be sufficient. If not, you can download the root certificate from LetsEncrypt.
Client TLS certificates are also supported, and may be used for identification to services. For instructions, see our guide on CertFP. If you have connected with a client certificate, has client certificate fingerprint f1ecf46714198533cda14cccc76e5d7114be4195 (showing your certificate’s SHA512 fingerprint in place of f1ecf46…) will appear in WHOIS (a 276 numeric).
Accessing Libera.Chat Via Tor
Libera.Chat is reachable via Tor using our onion service.
Configuration requirements with details below:
Update torrc configuration file to map to the onion service.
Configure your client to use your Tor SOCKS proxy (typically localhost:9050).
Configure public-key (not plain) SASL authentication.
Connect to palladium.libera.chat.
# torrc entry for libera.chat onion service
MapAddress palladium.libera.chat libera75jm6of4wxpxt4aynol3xjmbtxgfyjpu34ss4d7r7q2v5zrpyd.onion
This service requires public-key SASL authentication using either the EXTERNAL or ECDSA-NIST256P-CHALLENGE (but not PLAIN) mechanisms. See our guide on setting up CertFP for more information.
Some clients lack SOCKS4a or later support. In this case you will need to change your torrc file to map a private IP address to the onion service address instead and disable TLS hostname verification in your client. Onion service names securely identify a service. The connection will still be secure.
Using CertFP
As an alternative to password-based authentication, you can connect to Libera.Chat with a TLS certificate and have services recognise it automatically.
For SASL EXTERNAL to work, you must connect over TLS.
Creating a self-signed certificate
In order to follow these instructions, you will need the openssl utility. If you are using Windows and do not have a copy, you might consider using Cygwin.
You can generate a certificate with the following command:
openssl req -x509 -new -newkey rsa:4096 -sha256 -days 1096 -nodes -out libera.pem -keyout libera.pem
You will be prompted for various pieces of information about the certificate. The contents do not matter for our purposes, but openssl needs at least one of them to be non-empty. This certificate will last about 3 years, so consider setting a calendar reminder.
The .pem file will have the same access to your NickServ account as your password does, so take appropriate care in securing it.
Inspecting your certificate
The expiration date can be checked with the following command:
openssl x509 -in libera.pem -noout -enddate
The fingerprint can be checked with the following command:
openssl x509 -in libera.pem -noout -fingerprint -sha512 | awk -F= '{gsub(":",""); print tolower ($2)}'
Connecting to Libera.Chat with your certificate
IRC clients generally differ in where they look for a certificate and how you configure them to offer it to the server. If yours is not yet listed here, advice in this section is unlikely to apply, but guides may be available elsewhere on the web.
Irssi
Move the certificates you created above to ~/.irssi/certs
mkdir ~/.irssi/certs
mv libera.pem ~/.irssi/certs
Configure your /server entry for Libera.Chat to use this certificate. You may need to adapt this example for your existing configuration (the network and hostname should match what you already use).
/server add -tls_cert ~/.irssi/certs/libera.pem -network LiberaChat irc.libera.chat 6697
For the first time, connect to Libera.Chat using password authentication so that you can add the certificate fingerprint to NickServ.
/connect LiberaChat
Now follow the instructions to add the fingerprint. When done, you can switch the authentication to certificates.
/disconnect LiberaChat
/network add -sasl_password '' -sasl_mechanism EXTERNAL LiberaChat
/connect LiberaChat
If you did everything right you should now be authenticated using your certificate.
weechat
Move the certificates you created above to ~/.weechat/certs
mkdir ~/.weechat/certs
mv libera.pem ~/.weechat/certs
Now disconnect and remove the current Libera.Chat server(s). Re-add it with the SSL flag, using your newly generated certificate. Note that these commands are just examples, you have to adapt them to your current servers.
/set irc.server.liberachat.addresses irc.libera.chat/6697
/set irc.server.liberachat.ssl on
/set irc.server.liberachat.ssl_verify on
/set irc.server.liberachat.ssl_cert %h/certs/libera.pem
/set irc.server.liberachat.sasl_mechanism external
and then reconnect to Libera.Chat.
znc
Refer to znc’s official documentation.
HexChat
Place the .pem file in certs/client.pem in the HexChat config directory (~/.config/hexchat/ or %appdata%\HexChat). Note that the certs directory does not exist by default and you will have to create it yourself. Once the file is there, all subsequent SSL connections will use the certificate.
If you connect to multiple IRC networks, you should keep in mind that using the filename certs/client.pem will send the same certificate to all networks. If you prefer per-network certificates, use the name of the network exactly as it appears in the network list (Ctrl-S), including capitalisation and punctuation (e.g. certs/libera.pem or certs/Example Server.pem).
Konversation
Create the .pem file as per above, then place it wherever you want. Start Konversation, then open the Identity dialogue by either pressing F8 or via the Settings menu entry. Choose the identity you use for the Libera.Chat network or create a new one. In the part Auto Identity you have to choose SASL External (Cert) as the Type for SASL External or SSL CLient Certificate for CertFP. SASL External requires at least version 1.7 of Konversation. Optionally fill in your account name in the Account field. You can then choose the certificate you created with the file picker or enter the path manually in the field next to it. Once done, apply the configuration and (re)connect to Libera.Chat.
Revolution
Create the .pem file as per above, transfer it to your Android device, and place it wherever you want (Downloads is a common location). Start Revolution and navigate to the Manage servers screen if you are not there already, long-press on the server you wish configure certFP for, and select Edit. When presented with the Edit a server screen, tap on Authentication mode and select Client certificate (CertFP), then tap on IMPORT PEM and navigate to where where you put the pem file and select it. Tap the tick symbol on the top right of the Edit a server screen to save.
Alternatively, Revolution has the ability to generate a client certificate for you. Once you are presented with IMPORT PEM, there will also be an option to CREATE NEW and when you tap this, a certificate will be randomly generated and a certificate fingerprint will be displayed. Tap the tick symbol on the top right of the screen to save.
Add your fingerprint to NickServ
You can then check whether you have a fingerprint by using whois on yourself:
/whois YourOwnNick
...
YourOwnNick has client certificate fingerprint 959c0bdfa9877d3466c5848f55264f72f132c657b002b79fda65dbe36c67f4bb3d2a3e2e9925cb5896a53c76169c5bb71b7853bd90192068dc77f4b20159a1d8
...
To allow NickServ to recognise you based on your certificate, you need to add the sha512 fingerprint to your account (you will need to log in by other means in order to do so).
You can then authorise your current certificate fingerprint:
/msg NickServ CERT ADD
In the future, any connections you make to Libera.Chat with your certificate will be logged into your account automatically. Optionally, or if you wish to connect via Tor, you can enable SASL with the EXTERNAL mechanism.
Channel registration
Channel Namespaces
Our policies outline that channels on Libera.Chat fall into one of three categories and two namespaces. Channels that begin with only a single # character are either project or community channels. Channels that begin with two # characters are informal channels.
Project Channels
Project channels are reserved for on-topic channels as per our on-topic projects, represented by owners with an official claim to that name. A registered project as per the registration below can claim ownership over project channels bearing the group’s names or name prefixes. For example, Libera.Chat itself owns the channel #libera and all channels beginning with #libera-. As per our policies, these channels do not expire.
Community Channels
Community channels are reserved for on-topic channels as per our community groups. An official claim to the name is not needed, but not having it bears the risk of losing the channel should an on-topic entity with a valid claim start an official presence on Libera.Chat. Staff will try to find a good solution for both parties in such cases.
Informal Channels
Informal channels are for topics not covered by our on-topic projects. As per our policies, such channels can exist on Libera.Chat as long as they do not disturb the operations of our network and our project and community channels, and adhere to the network policies. Informal channels are given out on a first-come, first-served basis. They will expire if unused for a long time, see our policies for details regarding when this occurs. You can contact us on IRC with a request to take over an expired secondary channel.
Registering a channel
How to register a channel depends on what type of channel described above it is.
Project channels
Primary channels in the namespace of an already registered project can be registered directly via ChanServ’s REGISTER command. So if e.g. the project “MyFossCalendar” wants to add #myfosscalendar-social to the existing channels, they can just grab it. For Projects not yet registered as such with us, please see project registration. If you like to add additional channel namespaces to your existing project, please contact the projects and community team at [email protected].
Community channels
Community channels in the namespace of an already existing community can be registered directly via ChanServ’s REGISTER command. So if e.g. the owners of #linux would like to add #linux-social to the existing channels, they can just grab it. For namespaces not yet registered as such with us, please see community registration.
Informal channels
Informal channels that are not already taken can be registered by any user in it who has channel operator status, which is usually the first user to join an empty, unregistered channel. In this case you can use the REGISTER command in chanserv to register it to your account. See /msg ChanServ help REGISTER for details. If a channel is unregistered but nobody has operator status, please contact network staff and we shall see if we can find a solution that is acceptable for the local community.
Project registration
Project registration allows your project or organisation to have an official representation on our services and relationship with us.
On-topic projects
Projects considered to be on-topic for Libera.Chat are primarily free and open-source software projects, and other peer-directed projects, for instance Linux User Groups (LUGs), student societies, hacker- or makerspaces and other collaborative efforts. It can also cover projects/companies of general interest to our user base.
Claim to the name and representation
A claim to the name is given if your project is on-topic as per the above and named like that, or commonly called / abbreviated that. In case of name clashes, e.g. other on-topic projects already present using the same name or there being obvious trademark issues, our team will try to find a good solution. The same applies if your name contains characters that can’t be used on our services for technical reasons.
The registration should be either done by or have received the official blessing of someone who is able to speak for the project. This could be:
The project founder
A lead developer
Someone in a management position
A board member
…
How to register as a project
We recommend you contact us as per the Projects & Community team section before registering, so we can already check whether your project is likely to be considered eligible to a registration. Once done, we will need the following information from you:
# About your project
Your project name(s):
Your project description:
Can we list your project publicly, such as on the libera.chat website:
Libera Chat staff member you have discussed this registration with:
Links to places we can find out more about your project:
(e.g. website, source code repositories or similar)
# About you and your staff
Your NickServ account:
Your relationship to / position in the project:
NickServ of group contacts and if their status is hidden/public:
# Channels and cloaks (see below)
Channels you'd like to claim:
(typically #projectname and #projectname-*)
Would you like ONLY group contacts to be able to register these channels with
ChanServ?:
Cloak namespaces you'd like to claim:
(typically projectname/*)
Group contacts are the members in your project that will be the official interface between Libera.Chat and your organization. They are the ones who can claim channels in your namespace(s) and request cloaks for your members/users. You can tell us whether these should be visible to the public or not. If you need specific rules or abilities for your group contacts, check with our team to get the option that fits your structure best.
Please send this information as an e-mail to [email protected].
Our team will then get in touch with you and do a claim verification. These are done per case and usually contain some sort of check of domain / code repository ownership or the likes.
Benefits of registered projects
Registered projects can profit from the following benefits:
Channels in their namespace can be claimed
Optional cloaks are available for members. These replace the hostname part with a custom string, e.g. @yourproject/developer/alex or @yourproject/taylor
We offer to send messages about important releases or events of your project as a “wallop” message to all our users who opted in to receiving these
Community registration
Community channels on Libera.Chat are for topics that would otherwise be eligible for a project registration but do not have an official representation (e.g. #linux), or are significantly relevant to our intended userbase (e.g. #windows).
How to register as a community
We recommend you contact us as per the Projects & Community team section before registering, so we can already check whether your community is likely to be considered eligible to a registration. Once done, we will need the following information from you:
# About your community
Your community name(s):
Your community description:
Can we list your community publicly, such as on the libera.chat website:
Libera Chat staff member you have discussed this registration with:
# About you and your staff
Your NickServ account:
Your relationship / affiliation with the community:
NickServ of group contacts and if their status is hidden/public:
# Channels and cloaks (see below)
Channels you'd like to claim:
(typically #communityname and #communityname-*)
Would you like ONLY group contacts to be able to register these channels with
ChanServ?:
(The cloaks will be formatted like this:
about/YourCommunityNameHere/name or about/YourCommunityNameHere/role/name)
group contacts are the members in your community that will be the official interface between you and Libera.Chat. They are the ones who can claim channels in your namespace(s) and request cloaks for your members/users. You can tell us whether these should be visible to the public or not. If you need specific rules or abilities for your group contacts, check with our team to get the option that fits your structure best.
Please send this information as an e-mail to [email protected], our team will then get in touch with you.
Benefits of a community
Registered communities can profit from the following benefits:
Channels in their namespace can be claimed (with /msg ChanServ CLAIM)
Optional cloaks are available for members. These replace the hostname part with @about/yourcommunity/custompart, and can be requested on #libera-communities.
The Projects & Community Team
The Projects & Community Team comprises, among others, e, Fuchs, kline and Swant; together they will act as your liaisons during the project registration or topic claiming process and throughout your tenure on the Libera.Chat network. If you wish to discuss the registration process, find out if Libera.Chat could be a good fit for your project or register your project, please feel free to drop any of the team members a line on IRC. If none are online, feel free to reach out to staff in general and they will forward your request to the team, which will get back to you as soon as possible. Once you have discussed your project with a staff member, you’ll be asked to email [email protected] with the details of your request as per the above.
Comments