cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/kube-kubelet-bc01n01.hswaw.net.cert b/cluster/certs/kube-kubelet-bc01n01.hswaw.net.cert
index aedde0e..9ab8d52 100644
--- a/cluster/certs/kube-kubelet-bc01n01.hswaw.net.cert
+++ b/cluster/certs/kube-kubelet-bc01n01.hswaw.net.cert
@@ -1,31 +1,12 @@
 -----BEGIN CERTIFICATE-----
-MIIFVjCCBD6gAwIBAgIUXKffSPzBdHHsKI5PV1MaBtJdXG4wDQYJKoZIhvcNAQEL
-BQAwgYMxCzAJBgNVBAYTAlBMMRQwEgYDVQQIEwtNYXpvd2llY2tpZTEPMA0GA1UE
-BxMGV2Fyc2F3MRswGQYDVQQKExJXYXJzYXcgSGFja2Vyc3BhY2UxEzARBgNVBAsT
-CmNsdXN0ZXJjZmcxGzAZBgNVBAMTEmt1YmVybmV0ZXMgbWFpbiBDQTAeFw0yMjA0
-MDQxNjQ4MDBaFw0yMzA0MDQxNjQ4MDBaMIGFMQswCQYDVQQGEwJQTDEUMBIGA1UE
-CBMLTWF6b3dpZWNraWUxDzANBgNVBAcTBldhcnNhdzEVMBMGA1UEChMMc3lzdGVt
-Om5vZGVzMRAwDgYDVQQLEwdLdWJlbGV0MSYwJAYDVQQDEx1zeXN0ZW06bm9kZTpi
-YzAxbjAxLmhzd2F3Lm5ldDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIB
-AMCCerGanIpykEvuJnxkz1ZqoHDvrAfM7Yyb7Ca7+njBPmrg7WVkHFQdn1ylSvRZ
-69vrtosUheOfkzAPT5sqRhQ/8VIAoHA1bXhAW19NmkK5I1FyWGjjGn1sjfmEvk4o
-cLf6gcvErRJdPbGz/vzBZ0X0FeCfqGPcUnLZYbh8wCdS9PkqeEq6m2CH6Toxb8jx
-Kz1fZbJf3gVnGxR3xUA9Fj8FmhpyOvnTXVa4mLh67x197lII1t86yTuc+8uwVQUR
-iC8PK15hgUm2q+MNWlNlXAxq0V5ZnZfiI9Qwdh43TqCKPI2kmgEu8ehT0qICbr6J
-SaB8OASLqhb3xI5CQLeZtX2tTdyQDD9DpGKquQHjdZ7uEA437KsG9MHLhrRW48RY
-O4bMgwhQ9V0+5Hc1NWOrccn4qmULwgFXaDWMjId5jRcWxBKtRW+jy0Vgqo4iFwZk
-b50unO0/VMmNw5bQQpfMnH1ubbctialjZqUevrV8zqcVaUMrHqdQbVjiitVzZghg
-FQL2wALYLNYt+dXYAQan2OqEaL+WuCUeP1LGlhXHqxfNjhXJjj1U/EAvEnNzFQ0M
-QQwe1QTYA4k0i1GlbbvtK4/PFECY/YzVgm70/lnH5AkkC+dQduQ69KTZx2YDD0iD
-QaaisNvK2CqFoim0cjiBWWTlpUxv3XF0TCnlso18z5EVAgMBAAGjgb0wgbowDgYD
-VR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNV
-HRMBAf8EAjAAMB0GA1UdDgQWBBRQZwM3WgGW+l8MKQBF2DZ5IWBh6jAfBgNVHSME
-GDAWgBSYMl0OTzMe+wnpiSQTFkJqgNGZ0DA7BgNVHREENDAyghFiYzAxbjAxLmhz
-d2F3Lm5ldIYdc3lzdGVtOm5vZGU6YmMwMW4wMS5oc3dhdy5uZXQwDQYJKoZIhvcN
-AQELBQADggEBADGEplxPFZ7CRABGb7JImNm6hMxz7TORCkR5VtShSf/xG3gEo+a1
-Oqw0j0af3zuPLlugBZ3TfklpEzJAyVHhQHu2z7Wly0f5FAQ9egMRAVISIz+dVeIh
-BywsgwgnvDeOjQPYg422Lsgm0Br6NlgxpFqBdCebytjUP95a7wsYwiH6H0PL7eCk
-HgxRUe43Lu6RpVfa+Iuszdx35m5crvHN5NdtqTckJH6d23pjjVAfJ/6VOVpS1Jzv
-U2eYLw1xwMu8TLNY3qjvPSdrfMJ8/48U7dSLQ2g8kMJcqpR0+nUTzrmmXQT41fVC
-zBhQTU142SMEUZnO95rCao19uUuAOItoYoQ=
+MIIBrTCCAV+gAwIBAgIQZbN5QcEmxO13HJiCqRRl2DAFBgMrZXAwHTEbMBkGA1UE
+AxMSa3ViZXJuZXRlcyBtYWluIENBMCAXDTIzMDMzMTE3NTk0NFoYDzk5OTkxMjMx
+MjM1OTU5WjA/MRUwEwYDVQQKEwxzeXN0ZW06bm9kZXMxJjAkBgNVBAMTHXN5c3Rl
+bTpub2RlOmJjMDFuMDEuaHN3YXcubmV0MCowBQYDK2VwAyEAP0FKz99+82ernmEP
+uSiClRXUZAYbE1vborosXYalVy2jgZAwgY0wDgYDVR0PAQH/BAQDAgWgMB0GA1Ud
+JQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAfBgNVHSMEGDAWgBTJxD7BNaxzSU17
+7mLGAkDEg5xzDzA7BgNVHREENDAygh1zeXN0ZW06bm9kZTpiYzAxbjAxLmhzd2F3
+Lm5ldIIRYmMwMW4wMS5oc3dhdy5uZXQwBQYDK2VwA0EAWMUaRIyKCbA19mOZFsY5
+fogxsN8zgvqEbUBoz+AjjIVrFV1DkUt/DaicjMR7ImiB/ilZ6Oq7GkqrvpkT4hRO
+Bg==
 -----END CERTIFICATE-----