It seems that, if you want to deploy a certificate (using a Certificate configuration in a Policy),
you also have to deploy an Authentication policy, according to the warning shown below:

So we created an Authentication Policy too, and it surprises us to see that it's not necessary to define a User Password Policy.
The 'Device Administrator Password' setting is enough.

Is this logical?
Because, when installing a certificate on a non-MobiControl-managed device (plain, out-of-the-box Android),
one must configure a pincode on the device before a certificate can be installed...
SOTI Support has been contacted & have indicated to us that 'if it's working for you right now, it will be ok',
but I'm interested in the deeper philosophy behind the above... ;)