Centos 6.4 changed the NSS library to reject X.509 certificates which
are signed with MD5:
"[VALID] The upstream Mozilla NSS disabled support for MD5 hash
signed certificates in the 3.14 release, which was added to CentOS
6.4. More details and workarounds can be found in this Fedora bugzilla
report https://bugzilla.redhat.com/show_bug.cgi?id=895513"
This change can be reverted when the world has changed from MD5 to something else :)