cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/ca-etcdpeer.crt b/cluster/certs/ca-etcdpeer.crt
index e335f35..0022428 100644
--- a/cluster/certs/ca-etcdpeer.crt
+++ b/cluster/certs/ca-etcdpeer.crt
@@ -1,23 +1,10 @@
 -----BEGIN CERTIFICATE-----
-MIIDyjCCArKgAwIBAgIUFEezYLKVElTQapJv+PMKnH5VMCwwDQYJKoZIhvcNAQEL
-BQAwfTELMAkGA1UEBhMCUEwxFDASBgNVBAgTC01hem93aWVja2llMQ8wDQYDVQQH
-EwZXYXJzYXcxGzAZBgNVBAoTEldhcnNhdyBIYWNrZXJzcGFjZTETMBEGA1UECxMK
-Y2x1c3RlcmNmZzEVMBMGA1UEAxMMZXRjZCBwZWVyIGNhMB4XDTE5MDQwNjE3NTkw
-MFoXDTI0MDQwNDE3NTkwMFowfTELMAkGA1UEBhMCUEwxFDASBgNVBAgTC01hem93
-aWVja2llMQ8wDQYDVQQHEwZXYXJzYXcxGzAZBgNVBAoTEldhcnNhdyBIYWNrZXJz
-cGFjZTETMBEGA1UECxMKY2x1c3RlcmNmZzEVMBMGA1UEAxMMZXRjZCBwZWVyIGNh
-MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsuRyVtX1kTDeWHKYJA/q
-H8SUpvbdtgMZKfbeXeUTIOH3nqiO2LePvzlwADzTOyi8uCdGmT4y87BxgzOW/Ghj
-eCr8NYMC3f/sKaJwZGenqoOnAn0qkvLSE5mVDSp5xJPqeYgRTJMQxjC5JfwAZinT
-uZNdqnS+RDt7EfujiP8bJJE4hHTue8v0+OPN5XeL35dotDbVmHFk/NEZJrtYK6lG
-fkY97TWgqCU0v+K4TRIDJBh9LX867LgxuW3VhNYZ8xc8PRAfnnPF3g+fnzAGcuhk
-YptBA9di6r5YESdK86IGI1RaQ3VKF/fPQ0789RbMsN7ZV/vQVYnjfmvAHr5n2Fxh
-QwIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
-HQ4EFgQULXuar2iqGaTMKoi++HbkvSenJA4wDQYJKoZIhvcNAQELBQADggEBAFJQ
-58q8yXOzYIE0skbSZYXVo4U3Sc/10r5gdbhPTN5XYl+3cK9ier8CBQEv3vKfNtjD
-My+X6OeQr8NSGK5ZNK+ijlv9h8g/NFFEMyRFiULrDt8MiUFQysLMuVdNSozz40P6
-+TAx5S6cnsIrr93+qCoF45Lfzx8lB/REWpa+Z7Tn+40taCepaJJmrEGkwI9XqVsp
-1pB6G4g1qsdFoLgUgy85RjA14Nw2MSxfwUcxGEvXbj1914ktkAiWA8HH/IKIbS4B
-1hoQuAsO46+mnqZHV+qV6KyIfOxafApHY2qmtvSioRRL9eXF8qpVMkr0wrb8WYox
-hkWi5S3B6YRE9Ld9UdI=
+MIIBWTCCAQugAwIBAgIQfUsnDAuyirtt6K6cdD8BOjAFBgMrZXAwFzEVMBMGA1UE
+AxMMZXRjZCBwZWVyIGNhMCAXDTIzMDMzMTExMjcyMloYDzk5OTkxMjMxMjM1OTU5
+WjAXMRUwEwYDVQQDEwxldGNkIHBlZXIgY2EwKjAFBgMrZXADIQB1Wg0r5Fn1ifKP
+5R3gHptr/sKPJ4JpmermY5VoPLqnC6NrMGkwDgYDVR0PAQH/BAQDAgGGMCcGA1Ud
+JQQgMB4GCCsGAQUFBwMCBggrBgEFBQcDAQYIKwYBBQUHAwkwDwYDVR0TAQH/BAUw
+AwEB/zAdBgNVHQ4EFgQUC8DBq1ngR0i8hOQ7XRY525ufLvkwBQYDK2VwA0EABU36
+StuVX1k35rgxuqfSkkzjeqr4Uk2Yc+5YSV2qV0XctlZOEOUAtAbaBMOQ41EpeZcH
+tQ4P+5PFMoiroByOCA==
 -----END CERTIFICATE-----