This thread is a bit old and I thought you had figured it out.
Unfortunately, in my Express lab with a two way trust I wasn't able to reproduce the behavior, but here's what you can do.
Under /usr/share/centrifydc/bin there should be a binary for ldapsearch. Try to use that binary to search for the expiration attribute as a straight ldap query. This way you can compare and display the results vis'a'vis adquery user.
If the results are different, my only suspicion is a bug or a corrupted cache. Make sure you're using the latest version of Centrify.
Please post your results, if that's the case I will file a bug on your behalf.