> to support use of a runtime dynamically-derived trust engine per invocation (via SignatureValidationParams) I am pretty clueless, here, but ... under what kind of conditions would the trust engine be determined dynamically ? For algorithms requested or preferred per profile ?