Instead of running the node in "enroll + authenticate" or "authenticate" modes, change the system to run the node without a mode, but instead expose RPC to switch into a particular mode dynamically.
The validator authentication app has to change accordingly - there should be two buttons for switching into "enroll" and "authenticate" mode, and a new UI (or a separate screen) for displaying the node status.