Our old self signed ssl cert has expired. Rather than need to maintain a
CA for infracloud or sort out how we want to sign things lets just go
ahead and use our snakeoil cert on the controller. The two big drawbacks
to this approach are the long length of time this cert is valid for and
it forces us to use a single controller host per cloud.
Note that private hiera will have to be updated with the private key
that corresponds to this (is the private portion of the snake oil cert
on controller00.vanilla).
Change-Id: I70de0416534f1b202c7c66c127777b7edc17486e