Required access levels to perform user recertification by Notes mail

Greetings, wise people. I wonder if anyone has any words on an issue we are experiencing here. We have adminstrators that are tasked with recertifying users (by Notes mail). They have Author access to the Domino Directory, with Create Documents and UserModifier role (among other roles). They are also listed as a group in the Administrator field of the Person documents.

When they recertify a user, by Notes mail, the process appears to complete without error. However, the next time the user signs on they get an error message saying “Error updating local ID file: The information in the supplied certificate from the address book entry is out of date”.

I can make the error message stop by pasting the public key from the user’s id file into the Person document. This tells me either the ID file or the Person document was not updated with the new public key. Since the design of the Person document requires Editor access or above in the Certificate field, I am assuming that my Author-access administrators are unable to update the Person document with the new public key. And if this is the case, why does documentation state that an admin only needs Author access and some roles to do a recertification?

Any advice on this is welcome. I feel like I’m going around in circles on this.

dave