Presently the spec [OnEncrypt](https://github.com/awslabs/aws-encryption-sdk-specification/blob/master/framework/kms-keyring.md#onencrypt) section of the spec says that the keyring should use a "client that calls the AWS region specified in the generator ARN". In cases where the keyring's generator is an alias (e.g. "alias/MyCryptoKey"), there is no way to determine the region to make call is.