According to this TechNet article Machine Accounts (Computer Objects) reset internal passwords every 30 days.
Let's assume that this server is running IIS with Kerberos SSO, so it has SPN HTTP/ and client has cached Kerberos ticket it's using to access resources on this server.
If machine account for IIS server password resets every 30 day - would it invalidate cached Kerberos ticket on the client and prevent access until ticket expires or gets purged manually on the client using "klist purge".
Is there a workaround for this? Can IIS server force client to renew Kerberos ticket?