Certificate trust policy not saving after account change
I have an M1 14" that is managed with JAMF (not sure that is relevant other than the story). IT made a change to my account (changed from a 'mobile' standard account to local admin, and also changed the UID). It seemed fine except for deleting my login keychain. But then it couldn't connect to the WiFi, which required a certificated to be accepted. It turned out that the account is unable to save changes to trust settings of a certificate. (Open the certificate in keychain access; change trust settings; close; enter password; reopen certificate and settings haven't changed.)
The problem started on Monterey, and we updated to Ventura to see if that might help. It did not.
A newly-created account on the laptop *is* able to change the trust settings, so there is some problem with the first account. Is this possibly some issue in the ~/Library or would it be in a system-level user account setting (like in /var/db/dslocal/nodes/Default/users)? I have tried resetting the ~/Library/Preferences to no avail. (Although that did fix another problem with search not working in System Preferences)
There was one other question like this here, but it didn't have an answer: Certificate trust policy not saving
MacBook Pro 14″, macOS 13.4