cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/kube-apiserver.cert b/cluster/certs/kube-apiserver.cert
index 4186b6c..b78083b 100644
--- a/cluster/certs/kube-apiserver.cert
+++ b/cluster/certs/kube-apiserver.cert
@@ -1,30 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIFOzCCBCOgAwIBAgIUewr6xBQ9YR/GYKoblU+eCaA2ddYwDQYJKoZIhvcNAQEL
-BQAwgYMxCzAJBgNVBAYTAlBMMRQwEgYDVQQIEwtNYXpvd2llY2tpZTEPMA0GA1UE
-BxMGV2Fyc2F3MRswGQYDVQQKExJXYXJzYXcgSGFja2Vyc3BhY2UxEzARBgNVBAsT
-CmNsdXN0ZXJjZmcxGzAZBgNVBAMTEmt1YmVybmV0ZXMgbWFpbiBDQTAeFw0yMjEw
-MDIxMzI1MDBaFw0yMzEwMDIxMzI1MDBaMGQxCzAJBgNVBAYTAlBMMRQwEgYDVQQI
-EwtNYXpvd2llY2tpZTEPMA0GA1UEBxMGV2Fyc2F3MRcwFQYDVQQLEw5LdWJlcm5l
-dGVzIEFQSTEVMBMGA1UEAxMMazAuaHN3YXcubmV0MIICIjANBgkqhkiG9w0BAQEF
-AAOCAg8AMIICCgKCAgEAsx1dks+6hu3dWLizbUf5egqRfax9oaKJn7H2+F0ndoIX
-OJNi13aIAWjwD8OBza5xVTmzv1o1jF0AksHqioCjDbMF4MwdYUToj0ELysSX4eeG
-8Ho8Fq+sSXK3/TSSB2zb/OzY+Ox2B6DQRQjv0a0XmxOXY2mIvHMb3bckhhoWchBD
-YY/HU3840wpsnLvj7zPcZCsmKhnWywWErLvBN9I/28GraTszOKS3+NId9OTPlESB
-s4xnSfNB25JJ+vVhbZaNB2oq2FJjeR7yytR54rC4M5rgPwiOjSc1Po7m+aeJa0EV
-Or4iUT+5kn+S4ckdkP9EkzYDZZENoz2A4BacjRE/JM16Xd/4Yp+O1lreTlEWOelD
-XeKcAkLm+ZePB0hYixuR3vRvfhca+UQv8Y3v8dAAit/shEULmas3JUTGt/OdLYH3
-rz8ITYOn9f5sYP5J81AQIM5IyW9NuGltN9Kv4IeBN+L8DQcLJ6WHBI54u8IrW4pl
-GU/heu8KNFxsLNaIOQY8elGZHYTL6UBs5MqFrk/AQK0qmyLS8oSa1WlzwbPiaNXq
-aE3Hl1VF+3A4qEx7y9NQmJr3x24YY7xGhfXXwz8Ac+OBct0sx/2u3W+NQ+u5zI1C
-CZQVKln1s/oO40pxTB1SAlIJW3Kd8gvcJ+ZdIiRJDTO3YWf8JcpNYrSe270r/W0C
-AwEAAaOBxDCBwTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEG
-CCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFKBFe5T0rvllN4ZQuSFH
-UGOcke7SMB8GA1UdIwQYMBaAFJgyXQ5PMx77CemJJBMWQmqA0ZnQMEIGA1UdEQQ7
-MDmCDGswLmhzd2F3Lm5ldIIja3ViZXJuZXRlcy5kZWZhdWx0LnN2Yy5rMC5oc3dh
-dy5uZXSHBAoKDAEwDQYJKoZIhvcNAQELBQADggEBAICzG8usQwna6lEieTwTm2u/
-g2e1k9s2+QFJn3X9/2v32lWWFlgKJenIuALfaeLq5ISoo7L0eiLy3Z+CKrlm3d17
-svvHNF76Kpdc4qv5p+R+2mmt558SHwUYLnbFL8omXb/JrtRUIY6ALBataqJUxOh7
-t8duPee+94++Gl4G3zitVzjOS3fBepxfCsiA6/ku2bYygJAU4TesYv8SjtITeXpa
-xX0IQB2Tp/3InECkkH+6bczi5eYOvuRfEfI0Dq/NjmHHKcaLtnzfXk2/5CQvkhAm
-kIz6tb65ax0OSd3jQ5QBlGn/lk66djxrqPJ298TgkrGYibd8wAryihgBDvql3Xc=
+MIIBjDCCAT6gAwIBAgIQE4AB6OJkrNroVln8m3IqRTAFBgMrZXAwHTEbMBkGA1UE
+AxMSa3ViZXJuZXRlcyBtYWluIENBMCAXDTIzMDMzMTEzMDk0OFoYDzk5OTkxMjMx
+MjM1OTU5WjAXMRUwEwYDVQQDEwxrMC5oc3dhdy5uZXQwKjAFBgMrZXADIQArO7UZ
+Nch+NbI772smnkBycEZxKKqPZYnPAKCU9JMbzKOBlzCBlDAOBgNVHQ8BAf8EBAMC
+BaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMB8GA1UdIwQYMBaAFMnE
+PsE1rHNJTXvuYsYCQMSDnHMPMEIGA1UdEQQ7MDmCDGswLmhzd2F3Lm5ldIIja3Vi
+ZXJuZXRlcy5kZWZhdWx0LnN2Yy5rMC5oc3dhdy5uZXSHBAoKDAEwBQYDK2VwA0EA
+F9y75TSuG/wdW5RDyboz4B2lxYrZ+NifYWIz19E5XfgjO92vHxCJ9R1Eje1jOSYh
+NwZ+Fq6Ce+mcqmQJ2bACAg==
 -----END CERTIFICATE-----