Can you paste your /etc/krb5.conf, we also auth against AD and if your password expires and requires a change, that should be done on a windows server on the AD domain. I've never seen this occur through the service console. I assume you used esxcfg-auth to configure your initial authentication with your domain controller?