Hello,
you need to update the Keytab in the PSE file if you change the password of the Service principal user on the Active Directory Domain, that's all.
What you see is the generation time of the Kerberos keys, but there are infinite valid.
The Kerberos service tickets have lifetimes but there will be generated on a per SNC session basis.
best regards
Alexander Gimbel