    so that we do not get into the same situation as the Geni Portal.
    All of the Cloudlab clusters are more then two years from the CA
    expiration, so this won't present a problem for a while, but we do have
    certificates floating around that are set to expire after the CA.
    User certificates we can regenerate as needed, slice certificates will
    age out before then.
    I bet this *is* a problem on geni racks where expiration is much closer
    to now.
