<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <br>
    <div class="moz-cite-prefix">On 2/5/14 10:47 PM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote cite="mid:CF186F9E.8640%25cantor.2@osu.edu" type="cite">
      <pre wrap="">

There's no existing DecryptionParameters for the action to use, so that's
why I didn't use it.
</pre>
    </blockquote>
    <br>
    Well, I assume you'd do it like I did the security-oriented
    MessageHanders:&nbsp; you just look for the presence of a
    SecurityParametersContext and the relevant -Parametesr, and use it
    if present.<br>
    <br>
    Actually, I should have said that upfront.&nbsp; That's IMHO what any
    signing/validating/encrypting/decrypting Action or MessageHandler
    should do.&nbsp; Look for that context and use that data.&nbsp; It was
    intended to be that simple.&nbsp; How that context gets populated, and
    with what data, is out of scope for the action/handler doing the
    crypto operation.&nbsp;&nbsp; The only real decision is, for a given
    subsystem, where does the SecurityParametersContext live.&nbsp; If might
    be that for simplicity it just lives directly under the
    ProfileRequestContext, but I don't know what general standard you
    guys have been using (maybe using injected lookup strategies, etc).<br>
    <br>
    Also related: For message signing, the presence/absence of the
    SecurityParametersContext data is what determines whether signing
    happens, pure and simple.&nbsp; Whether the context is present or has a
    particular -Parameters is (presumably) determined by the various
    signing and encryption flags from the profile config (or whatever,
    e.g&nbsp; however we implement 'conditional' - or not).<br>
    <br>
    <br>
    <br>
  </body>
</html>