BESClient -update-certificate ... "credentials are not in place"?

In trying to update an expired certificate on a client, we’re running into a process error I’ve not seen before":

Aborting client certificate refresh because credentials are not in place.

The same command (BESClient.exe -update-certificate <password> http://<server>:52311) works fine from another computer, so it’s not that the credentials are not set on the server but I’m not sure what credentials would be referred to on the client…

–It looks like the Client is not able to find its current certificates into the KeyStorage folder…–

sorry, the password is required only if the parent relay is configured as authenticating relay

The server being used in the command is configured as an authenticating relay.

Have a look here: Client certificate

The workaround is to temporary connect the client to a non-authenticating relay and do the certificate refresh without password.