ACME Server with reuse-key // LE Ending Expiration Notification

Of course you don’t; you pin public keys (more accurately, hashes of public keys), which is what I said. But you should be pinning the public keys of the certificate authority, not those corresponding to your own certificates.

Edit: previous discussion of this here:

If you need to be manually updating anything when you get a new cert, you’re doing something very wrong.

2 Likes