Adding a certification key, as in your CLI example, is just adding a public key. CA management requires a private key. Perhaps the CA.crt file that you are using has both, with the private key encrypted, so Yast CA management want to be able to access that private key.
It does have a .crt and a .pem file, which were both asked and added in the CA management dialogue, but it also asked for the password, which I have no idea what it is.