Good question, and I'm not 100% sure so I'll report back, but what I do know is that once enabled all your current keychain entries are copied to iCloud. After that I think you need to specifically use iCloud APIs to update that password, rather than the local one… that's the unclear bit. I'll investigate.