pam.setcred.support.reinitialize
This parameter specifies whether the PAM flag PAM_REINITIALIZE_CRED is supported and can be used to trigger creation of the credential cache and renew Kerberos tickets. The default is false, in which case the PAM_ESTABLISH_CRED flag is used to trigger creation of the credential cache and renew Kerberos tickets.
For example:
pam.setcred.support.reinitialize: false