I agree : it is prohibited to manipulate a signed applet from javascript, and the workaround is to rewrite the applet tag in javascript in the page document.
I found this source with a bit of theory proving we are right
http://docs.oracle.com/javase/tutorial/deployment/applet/security.html#jsNote