We still use the first cert (scl3) in production; we should keep it until we
roll out the new certs. We don't use the second existing cert (mdc1) yet;
let's replace it with a new cert that covers the non-scl3 servers.
remove old mdc1 cert
adds new scl3 cert. This will last past Aug30; we can remove it when
it's no longer needed
adds a new non-scl3 cert. We can keep this one until summer next year.
Coverage remained the same at 100.0% when pulling 91d35c5dc9cfd24df175f11b3444bb02c0fac0d7 on escapewindow:update-ssl into 69a7480b32dab39bf065090e7668231752953d40 on mozilla-releng:master.
We still use the first cert (scl3) in production; we should keep it until we roll out the new certs. We don't use the second existing cert (mdc1) yet; let's replace it with a new cert that covers the non-scl3 servers.