ds:KeyInfo as a ds:X509Data/ds:X509Certificate. This is the default signature behavior when no key-info element (x509Data, securityTokenReference, or keyIdentifier) is configured. It applies to signature only: an encrypt names the recipient's certificate with a keyIdentifier, since the recipient already holds it.Syntax
x509Data: {}
x509Data: {}