Add EKUS, or Extended Key Usage parameters, of id-kp-clientAuth and id-kp-serverAuth to the certificate that certmonge generates, which is used by haproxy to proxy public-facing hosts. This is necessary due to the criteria by which Firefox and related browsers validate which required extensions are acceptable when interpreting a certificate. Change-Id: Ideec7d23769e68ae1b738c0118ec061b195e3bd7 Closes-Bug: 1668775