cluster: partial cert bump

Done:

 1. etcd peer CA & certs
 2. etcd client CA & certs
 3. kube CA (currently all components set to accept both new and old CA,
    new CA called ca-kube-new)
 4. kube apiserver
 5. kubelet & kube-proxy
 6. prodvider intermediate

TODO:

 1. kubernetes controller-manager & kubernetes scheduler
 2. kubefront CA
 3. admitomatic?
 4. undo bundle on kube CA components to fully transition away from old
    CA

Change-Id: If529eeaed9a6a2063bed23c9d81c57b36b9a0115
Reviewed-on: https://gerrit.hackerspace.pl/c/hscloud/+/1487
Reviewed-by: q3k <q3k@hackerspace.pl>
diff --git a/cluster/certs/kube-kubelet-dcr01s24.hswaw.net.cert b/cluster/certs/kube-kubelet-dcr01s24.hswaw.net.cert
index b4d8260..634df9a 100644
--- a/cluster/certs/kube-kubelet-dcr01s24.hswaw.net.cert
+++ b/cluster/certs/kube-kubelet-dcr01s24.hswaw.net.cert
@@ -1,31 +1,12 @@
 -----BEGIN CERTIFICATE-----
-MIIFWTCCBEGgAwIBAgIUHVN+wQDar/QnbVXMiQMaNnZtfuswDQYJKoZIhvcNAQEL
-BQAwgYMxCzAJBgNVBAYTAlBMMRQwEgYDVQQIEwtNYXpvd2llY2tpZTEPMA0GA1UE
-BxMGV2Fyc2F3MRswGQYDVQQKExJXYXJzYXcgSGFja2Vyc3BhY2UxEzARBgNVBAsT
-CmNsdXN0ZXJjZmcxGzAZBgNVBAMTEmt1YmVybmV0ZXMgbWFpbiBDQTAeFw0yMjEw
-MDIxMzUzMDBaFw0yMzEwMDIxMzUzMDBaMIGGMQswCQYDVQQGEwJQTDEUMBIGA1UE
-CBMLTWF6b3dpZWNraWUxDzANBgNVBAcTBldhcnNhdzEVMBMGA1UEChMMc3lzdGVt
-Om5vZGVzMRAwDgYDVQQLEwdLdWJlbGV0MScwJQYDVQQDEx5zeXN0ZW06bm9kZTpk
-Y3IwMXMyNC5oc3dhdy5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoIC
-AQDBvci18rAPjP2MediOv0cSTS3Hi3qXKtfHODgvZ2Db4rf6fElbS5t982f6/Ox1
-ZzNmspz2qCQCzz5IXUX+G+zV3BFbHZQv3va2NnPJFdWaxCOH5IUt08rnOXgq5+Co
-A5doiF6n+MLAo+CQVl6xXFPv1ElD3SyDa0Ba0yh5yJGmdZ/KuCYD36ZSD/oZFdcA
-Gvau87YmCnSoqvZGY8+lmGQrdujjErMN7Bl+nE1sQrhjZO7jxyRjXf7qKSLUJcFh
-TED1Z95xe2phvWHnPbPi4XY4Gg4Y0Vo0YdU7EUG8OEX8KMsNzceZqtxhqx+oF+IL
-jzoxMunqcydRATBreNEhjWr6sKn1ruCEZ9pypCbw7T0hpqkcTomeE31bZZ7/VPOm
-ZPwScL0+X+i4UmAunNuY3rxijbhwdGeJznHfba3ETg+3JKoc28bQcfl8Y/SVon6L
-nK6HT+kVcvX6z91bRTIuYbcb7Tn4GqFh7OhMgbFvMl2IJT5J4n5zLADC3PcQs7uT
-vp+OeP3Z3uYhOIU4KCaBce0t6aDuMSgLXneuKb34wMJA8qRpN9L+D84jW6qlt09Q
-KgM13vvCi5+pI0Lth9hx3ga1kaIqbEHQPjnKiZBrkW6wPfwrKN/Uo7fauf1ZcH6U
-AgHwU4jUSixZBrumyUFrHWy2U1e8URK3+OGBZhGVBVwhYwIDAQABo4G/MIG8MA4G
-A1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYD
-VR0TAQH/BAIwADAdBgNVHQ4EFgQU98WJLNafrXaajcrVAVuoPlj3EhcwHwYDVR0j
-BBgwFoAUmDJdDk8zHvsJ6YkkExZCaoDRmdAwPQYDVR0RBDYwNIISZGNyMDFzMjQu
-aHN3YXcubmV0hh5zeXN0ZW06bm9kZTpkY3IwMXMyNC5oc3dhdy5uZXQwDQYJKoZI
-hvcNAQELBQADggEBAGH3O/Az/EWWYj9eH/n0OK5xsqsp/PYUXaVb6vgb+Pfga4ji
-ng8OJD5qA52Pp/K/3N9hgUBYL9UwfXX3cgx9iozGbxAcEBAeOvNxeOWJy1/60Q3C
-gZaVQPIUp3jD88aQdcWp4akapNFZbK1I49nIXn/WqgjUYpvQ/bk3CxdHRRLrvfZ3
-VqHnd3PxXSfcwrKvilor4C6BVLLWlIOinZVOoMuGJqoaJhV3hitWNKIBBetiZVVk
-/yauJIb2Ml7OpAp9+ZbgMsjF1ZH1lSEvYb69zlRyYBHWtnM6JYXJUoVXzLKIfJAX
-A+6qFpiCmPYPQiMt5ssSfa6S7Uk+zvKEu4GpGUQ=
+MIIBsDCCAWKgAwIBAgIQIou0S4woMeN5795tFvuD3jAFBgMrZXAwHTEbMBkGA1UE
+AxMSa3ViZXJuZXRlcyBtYWluIENBMCAXDTIzMDMzMTE3NTk0NFoYDzk5OTkxMjMx
+MjM1OTU5WjBAMRUwEwYDVQQKEwxzeXN0ZW06bm9kZXMxJzAlBgNVBAMTHnN5c3Rl
+bTpub2RlOmRjcjAxczI0Lmhzd2F3Lm5ldDAqMAUGAytlcAMhAGnfXhzOam+Owhmw
+MDKqJ2GsMXTr6ABBA09RAJAC9QKmo4GSMIGPMA4GA1UdDwEB/wQEAwIFoDAdBgNV
+HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHwYDVR0jBBgwFoAUycQ+wTWsc0lN
+e+5ixgJAxIOccw8wPQYDVR0RBDYwNIIec3lzdGVtOm5vZGU6ZGNyMDFzMjQuaHN3
+YXcubmV0ghJkY3IwMXMyNC5oc3dhdy5uZXQwBQYDK2VwA0EA7NpxFD/tzxBXQ534
+bkDKxST97zhuSOgW71vcc5XovzRy2YsuVIzBD3EnNR9egbg85yk+wz7hI7/Hy0yn
+uQ3ZAg==
 -----END CERTIFICATE-----