# Auto load configFile either from File Path or Raw String

**URL:** <https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934>\
**Category:** SDK Questions\
**Created:** [December 21, 2023, 8:13am UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934 "2023-12-21T08:13:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghostidentity](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/ghostidentity/32/1529_2.png) [@ghostidentity](https://openziti.discourse.group/u/ghostidentity)\
**Post date:** [December 21, 2023, 8:13am UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/1 "2023-12-21T08:13:28Z")

</div>

I have a usecase where i need to encrypt the configFile with TPM or Yubikey; so decryption will happen at runtime. I need to pass in raw string to ziti.newConfigFromFile or zitiContext , not a file path.

My suggestion is that, can we have process automatically detect the input and it load it automatically, regardless if its a file path or raw string ? The process should be able to detect if its a config file based on contents.

On the screenshot below (right image), zitiContext can't recognize the input because it's not a file path.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/8/8f2bc9ceeae1aae808f0b1b9aa280274e6500048.png)

---

<div class="post-metadata">

**Author:** ![ghostidentity](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/ghostidentity/32/1529_2.png) [@ghostidentity](https://openziti.discourse.group/u/ghostidentity)\
**Post date:** [December 21, 2023, 8:30am UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/2 "2023-12-21T08:30:27Z")

</div>

Note that, it would be okay to use filePath approach on the server on private network but when distributing the app to end users, there's a need to encrypt the certificate once enrolled.

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [December 21, 2023, 2:46pm UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/3 "2023-12-21T14:46:45Z")

</div>

Ziti's C# SDK ([GitHub](https://github.com/openziti/ziti-sdk-csharp?tab=readme-ov-file#readme)), correct? If so, mention "TheLumberjack" in this topic to page Clint.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [December 21, 2023, 6:03pm UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/4 "2023-12-21T18:03:29Z")

</div>

Hi @ghostidentity, the .NET SDK wraps around the ziti-sdk-c. It has a function to allow loading an identity from a string/byte array but it's not working at the moment. I filed this issue for the c sdk  
[Ziti\_load\_context does not process the pointer as json · Issue #602 · openziti/ziti-sdk-c · GitHub](https://github.com/openziti/ziti-sdk-c/issues/602).

I've filed this issue to expose a function in the .NET SDK that allows you to supply an in-memory representation (byte) [`ZitiContext` should also take a stream/byte array · Issue #67 · openziti/ziti-sdk-csharp · GitHub](https://github.com/openziti/ziti-sdk-csharp/issues/67)

Once that bug is fixed in the C SDK, I'll make a new .NET Native nuget package, and a new .NET SDK with the function you can try out.

---

<div class="post-metadata">

**Author:** ![ekoby](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/ekoby/32/14_2.png) [@ekoby](https://openziti.discourse.group/u/ekoby)\
**Post date:** [December 21, 2023, 7:03pm UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/5 "2023-12-21T19:03:41Z")

</div>

Ziti SDK allows you to use YubiKey as a hardware key (via PKCS#11 driver), that way the private key is not stored in the identity file, and, instead, the file just has a reference to the YubiKey slot.

This may remove the need to encrypt your identity file since it won't have sensitive data.

---

<div class="post-metadata">

**Author:** ![smilindave26](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/smilindave26/32/185_2.png) [@smilindave26](https://openziti.discourse.group/u/smilindave26)\
**Post date:** [December 21, 2023, 7:57pm UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/6 "2023-12-21T19:57:30Z")

</div>

Possibly helpful: [YubiKey by Yubico | OpenZiti](https://openziti.io/docs/guides/hsm/yubikey/)

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [December 21, 2023, 9:03pm UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/7 "2023-12-21T21:03:33Z")

</div>

Thanks to @ekoby, a new, fixed C SDK was published and I was able to publish OpenZiti.NET.0.9.23355.37738. I updated the WeatherSample (which I use to test) with usage:

> <https://github.com/openziti/ziti-sdk-csharp/blob/main/OpenZiti.NET.Samples/src/Weather/WeatherSample.cs#L37C21-L38>

---

<div class="post-metadata">

**Author:** ![ghostidentity](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/ghostidentity/32/1529_2.png) [@ghostidentity](https://openziti.discourse.group/u/ghostidentity)\
**Post date:** [December 22, 2023, 6:23am UTC](https://openziti.discourse.group/t/auto-load-configfile-either-from-file-path-or-raw-string/1934/8 "2023-12-22T06:23:32Z")

</div>

thank you @ekoby and @TheLumberjack I was able to confirm that it works. Here's the video for confirmation: [https://youtu.be/U8ugrSULOac](https://youtu.be/U8ugrSULOac) . WinUI3 can't use TPM to persist key because of its sandbox limitation so I had to use yubikey. I'm excited to use vTPM on Google Cloud to protect the certificate on the server side and further integration.

@smilindave26 I will likely deploy the app on microsoft store where end user can simply install it easilly without the need to install other tools.
