1. Make new CA cert for test that is both client-cert.pem andr client-ecc-cert.pem. 2. Use the new client-ca.pem cert in the test script. 3. Update renewcerts script to generate client-ca.pem.