The 'proper' way is to use a x509 or a kerberos token it can be difficult to
manage and distribute certificates though. Custom binary tokens are not too
different from a straight symetric encryption. You have to share some
information to encrypt and decrypt.
> What would be teh proper way to encrypt a SOAP response from a Web Service
> without using x.509 or Kerberos? I know I could do it using straight
[quoted text clipped - 5 lines]
> Would this be usable to encrypt the response as well as the issued request?
> What about a SecurityContextToken?
SecurityContextToken is generally used with a secure conversation