Description
When a service secured with a KerberosToken policy assertion responds to the client, it is incorrectly using a wsse:Reference to the original BinarySecurityToken in some cases. Instead it should be using a KeyIdentifier with the SHA-1 of the AP-REQ bytes.