How is a SAML token used by OWSM for identity propagation?
A.
 As each web service in a chain is invoked, OWSM generates a SAML token and 
inserts it in the WSSecurity header of the request message.
B.
 The SAML token, embedded in the X.509 certificate or Kerberos ticket, is extracted 
by OWSM and delivered to the next web service in the chain.
C.
 A SAML token is generated on invocation of the first web service in a chain and is 
stored in the Java Authentication and Authorization (JAAS) Subject so it can be used 
throughout the transaction by subsequent web services.
D.
 A SAML token is used to determine the destination address of the next web service 
in the chain.
A