an RST parameter can indicate which bulk-encryption algorithm an WIF-based STS is to use, when creating an encryptedDataToken (within which is a SAML assertion, say, with possibly wrapped proof keys).
How does one programmatically set the DEFAULT bulk-encryption algorithm?
I don't see any field in the config master-factory class.