<!--
{
  "availability" : [
    "iOS: 9.0.0 -",
    "iPadOS: 9.0.0 -",
    "macCatalyst: 13.1.0 -",
    "macOS: 10.11.0 -",
    "tvOS: 17.0.0 -",
    "visionOS: 1.0.0 -"
  ],
  "documentType" : "symbol",
  "framework" : "NetworkExtension",
  "identifier" : "/documentation/NetworkExtension/NEVPNProtocol/identityReference",
  "metadataVersion" : "0.1.0",
  "role" : "Instance Property",
  "symbol" : {
    "kind" : "Instance Property",
    "modules" : [
      "Network Extension"
    ],
    "preciseIdentifier" : "c:objc(cs)NEVPNProtocol(py)identityReference"
  },
  "title" : "identityReference"
}
-->

# identityReference

A persistent keychain reference to a keychain item containing the certificate and private key components of the tunneling protocol authentication credential.

```
var identityReference: Data? { get set }
```

## Discussion

The keychain item must have the <doc://com.apple.documentation/documentation/Security/kSecClassIdentity> class. In macOS, the system ignores this property for [`NEVPNProtocolIPSec`](/documentation/NetworkExtension/NEVPNProtocolIPSec) objects. On iOS, the system ignores this property for [`NEVPNProtocolIPSec`](/documentation/NetworkExtension/NEVPNProtocolIPSec) and [`NEVPNProtocolIKEv2`](/documentation/NetworkExtension/NEVPNProtocolIKEv2) objects. In these cases where the system ingores this property, set the identity using the [`identityData`](/documentation/NetworkExtension/NEVPNProtocol/identityData) property.

---

Copyright &copy; 2026 Apple Inc. All rights reserved. | [Terms of Use](https://www.apple.com/legal/internet-services/terms/site.html) | [Privacy Policy](https://www.apple.com/privacy/privacy-policy)