The recommended way to initialize the keystore and install certificates on a TC51 is using StageNow, which comes free of charge.
Do not mix manual cert installation and cert installation done by an MDM system or StageNow on one device!
I can confirm these sentiments. While StageNow is great for applying certificates on the devices, once it initializes the Keystore it becomes the owner of it, preventing your MDM/EMM from making direct changes. In the future, if you need to install another certificate or update the existing certificate for whatever reason, you would need to deploy the cert file through EMM and then run an StageNow generated MX profile for processing that cert.