cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/ca-kube-prodvider.cert b/cluster/certs/ca-kube-prodvider.cert
index 0b08699..a6e9e04 100644
--- a/cluster/certs/ca-kube-prodvider.cert
+++ b/cluster/certs/ca-kube-prodvider.cert
@@ -1,31 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIFQzCCBCugAwIBAgIUWy0KdFoBoGT7Wfw5ZsB2JRBvc+UwDQYJKoZIhvcNAQEL
-BQAwgYMxCzAJBgNVBAYTAlBMMRQwEgYDVQQIEwtNYXpvd2llY2tpZTEPMA0GA1UE
-BxMGV2Fyc2F3MRswGQYDVQQKExJXYXJzYXcgSGFja2Vyc3BhY2UxEzARBgNVBAsT
-CmNsdXN0ZXJjZmcxGzAZBgNVBAMTEmt1YmVybmV0ZXMgbWFpbiBDQTAeFw0yMjA5
-MDkyMjA5MDBaFw0yMzA5MDkyMjA5MDBaMIGsMQswCQYDVQQGEwJQTDEUMBIGA1UE
-CBMLTWF6b3dpZWNraWUxDzANBgNVBAcTBldhcnNhdzEbMBkGA1UEChMSV2Fyc2F3
-IEhhY2tlcnNwYWNlMSowKAYDVQQLEyFrdWJlcm5ldGVzIHByb2R2aWRlciBpbnRl
-cm1lZGlhdGUxLTArBgNVBAMTJGt1YmVybmV0ZXMgcHJvZHZpZGVyIGludGVybWVk
-aWF0ZSBDQTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAL/38OKQgrqI
-9WZKRubACVF1QUmZS9IIzcmmxsAJEvNwCirAr6Rx45G+uBlUx0PmHK+783Pa0WEO
-deTHpZZt5o6YrQGvEzkI9ckDraUjRcQEQewi3kygmAdPW6GMWZd7fjCjsEQ0Engc
-qJ7BkEWNfJYLh8VpEwPz1ClqFrlbHU55hbuvNNg3Ro0enFmTu3PPZYUIcdX3jyJz
-p/fsE7K/f2OhHG2ej0Ji2Ssz6Bo9bB6yHLMN1oYzGB5H8Xa5dQ6LqpU0wUBqtGC8
-06ZUfNA1gtpTOj+ApDX/OYucoOE422r1lT6SfgeBhHGN3xalcYyiPumFsCBUSq+B
-7oLRW3emWJcjlOdmhtx26yl5/XpONY8u/jPG56CnT3tNGPdYnpVQ/969NrKA7yd4
-TRA4rU6Nyg5f3x8Xrw5QPci5Uuz2X2feFy53x25i2tRT2fm5VabzdjsO9mXCZbl8
-BO8mLVJ4Ojw5ER/sIw/OME29+tcBL3j31OoBUAHo82ca4B0KJBCWDHrjDTlchFfT
-fQfFWuRluZaa1kGU/9hEuHe8wXNsMlkCW+68xZ5SXLX29ruhx7SoDk3+SMk1GMNv
-vZr6CjWer94OajPN+scW7Pol2mhqENWFsTDA0WFN0HwLjLna9vQJg6vZeobm3bWZ
-DWl93HqdKeINlp9Q0HQ7nR+LUkeodWf7AgMBAAGjgYMwgYAwDgYDVR0PAQH/BAQD
-AgGmMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAPBgNVHRMBAf8EBTAD
-AQH/MB0GA1UdDgQWBBRpjeqS08ZAgwwhQZnMEmrNN2PdszAfBgNVHSMEGDAWgBSY
-Ml0OTzMe+wnpiSQTFkJqgNGZ0DANBgkqhkiG9w0BAQsFAAOCAQEACAfpUfeejHhH
-/uTR9fMZTLP+6p1XUm68gVFK8AKd8EcltVaYtDjIFfP1Hv59jj6Af+0VH9Veqmoo
-h/B0tU+fTFG/9M6aJBVGYo7JfnG6KsSjIVRPl0zkfa/8RTqIHe4JRzP49ptiAp7d
-CVrBiEQR6zaiqyAZXuxN3TJ8JYgJzljd5nzku8+pSxP1wq5TQ/mkN7V9DNCdiXYP
-TA9CRTKwoiqIQsiwN5G8bi070HYkHb0aGXX3wzXkaYqLWTgGgW4ensItXty4lJFn
-cS3jKWvQaLHYCy2Fs+AiVFzYFC0IxwcDv9GGC6Lci/M9XKkaus5x4AFCpvNQYber
-a3WFKi5Q2w==
+MIIBlzCCAUmgAwIBAgIQA63/xPOSvZ9onKb3O7EFsTAFBgMrZXAwHTEbMBkGA1UE
+AxMSa3ViZXJuZXRlcyBtYWluIENBMCAXDTIzMDMzMTEyNTczOVoYDzk5OTkxMjMx
+MjM1OTU5WjAsMSowKAYDVQQDEyFrdWJlcm5ldGVzIHByb2R2aWRlciBpbnRlcm1l
+ZGlhdGUwKjAFBgMrZXADIQC5ZBgq9LF3+welMRx8eIVS7XOMFFeh/RhbZDcGpPsW
+paOBjTCBijAOBgNVHQ8BAf8EBAMCAaYwJwYDVR0lBCAwHgYIKwYBBQUHAwIGCCsG
+AQUFBwMBBggrBgEFBQcDCTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSCDPEq
+pWsmDJath+nc+WtOnfPBvDAfBgNVHSMEGDAWgBTJxD7BNaxzSU177mLGAkDEg5xz
+DzAFBgMrZXADQQDFX41Ol0uQWqxnNhR6Tc/GhwQuYIIz82vffcWUu9xlZ13VLhSz
+tJHSumwL/qjC/HNsLIuxnRE33HhoUNi1GlIL
 -----END CERTIFICATE-----