cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/ca-etcd.crt b/cluster/certs/ca-etcd.crt
index 03242d6..802e58c 100644
--- a/cluster/certs/ca-etcd.crt
+++ b/cluster/certs/ca-etcd.crt
@@ -1,23 +1,10 @@
 -----BEGIN CERTIFICATE-----
-MIIDwDCCAqigAwIBAgIUcCMt3kFz7oTod8UKTvyS/5KAU4AwDQYJKoZIhvcNAQEL
-BQAweDELMAkGA1UEBhMCUEwxFDASBgNVBAgTC01hem93aWVja2llMQ8wDQYDVQQH
-EwZXYXJzYXcxGzAZBgNVBAoTEldhcnNhdyBIYWNrZXJzcGFjZTETMBEGA1UECxMK
-Y2x1c3RlcmNmZzEQMA4GA1UEAxMHZXRjZCBjYTAeFw0xOTA0MDYxNzU5MDBaFw0y
-NDA0MDQxNzU5MDBaMHgxCzAJBgNVBAYTAlBMMRQwEgYDVQQIEwtNYXpvd2llY2tp
-ZTEPMA0GA1UEBxMGV2Fyc2F3MRswGQYDVQQKExJXYXJzYXcgSGFja2Vyc3BhY2Ux
-EzARBgNVBAsTCmNsdXN0ZXJjZmcxEDAOBgNVBAMTB2V0Y2QgY2EwggEiMA0GCSqG
-SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCq97dwVeisx1h8wwNFvCl0XGRHbrCxdOb7
-Znye8X9HZ6biM+o1WFfU1KPMr1+AIDukJwOXZLNYSdaUTjYRN7DFAvEwliScI5dK
-KaM+7ZNoLrEU4JR3I8sjUGjvVml19BlcGAwwV2waodE1a4THxQpyQClygfKlv1NQ
-SxQZ/Ju1b0wTf1Lupm1ZBXPyFmcs8/bgpkjkjMp3lF9JhU2E6Fzc3YOnto5ovSM2
-d46CN8BKyf+FXuTiEqwvsGuOOhby6Uwq3za7OtUu1qld0Ja5vQJgXrjxS1xTJPsB
-i83OqFHhiHhcqFxg5GfQgI0BxGTwPc1BW9e1ZyDumRbnjzRqFGETAgMBAAGjQjBA
-MA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTxWbhm
-TT7D50LugaPURn85U3X5DzANBgkqhkiG9w0BAQsFAAOCAQEAXSFdkAvgj4hynjs0
-X79FVZ4dvv8n+m4q6XJLqQIqfPwxs2FUUowQH7NiKrenZa0aaZVCcr5edcZ7F9n0
-u/HsvrGxumZkqIDT1KhO0/U0SS0nI28PdusAl1CTHX55rF6GVmUAhA2Vv7jJqAdy
-VKqC02AMrUels7Ebf/j+XveBxyEMnfFR5X4piVqip5VKcV0wk4leC3LWNlK6E7rE
-4qo9KM+HLtvj8I3u3MIigUZFSyaqnpMTut52CqsATOvR8qIgerpGKn3Mhq32iyWm
-RLbtLjicTSKWAOxbvfceEcZqJUXyi+akndx0XyJEbNG8tQ5ShIPeqNDXS4cVwgaE
-cMQ1hQ==
+MIIBTzCCAQGgAwIBAgIQEp1RM5CHVMEwy0lkViy9dDAFBgMrZXAwEjEQMA4GA1UE
+AxMHZXRjZCBjYTAgFw0yMzAzMzExMTU1MjlaGA85OTk5MTIzMTIzNTk1OVowEjEQ
+MA4GA1UEAxMHZXRjZCBjYTAqMAUGAytlcAMhAFS48WErN6bQRzSgWPzVOU1rb+Nr
+LxywAykg1vLa0deFo2swaTAOBgNVHQ8BAf8EBAMCAYYwJwYDVR0lBCAwHgYIKwYB
+BQUHAwIGCCsGAQUFBwMBBggrBgEFBQcDCTAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBTd0G1YWn+8LBYKlL7jTWY2Wypb1jAFBgMrZXADQQDBGfhtZEw1XzXhY1K/
+Hu7lJFRS+9Jt1hztg3UFMceKlzUHXC4SoFXLWDTg2UNIabCQs5PMFWRYCqLhaq0S
+Jb8O
 -----END CERTIFICATE-----