Just in case people haven't figured it out yet - ACM issues free wildcard certs :)!
http://aws.amazon.com/certificate-manager/pricing/
https://docs.aws.amazon.com/acm/latest/userguide/acm-certifi...
http://aws.amazon.com/certificate-manager/pricing/
https://docs.aws.amazon.com/acm/latest/userguide/acm-certifi...
Still very cool!
That said, SSL certs and domain renewals are the least interesting but high importance items of running an online business. As I'm already heavily deployed on AWS, I have no problem having them handle all of this for me, for what is free to me. (yes yes, not technically free)
http://security.stackexchange.com/questions/16085/how-to-get...
If a third party controls your keys, certificate pinning is useless to prevent against attacks from that third party or governmental agencies.
Not sure if this approach is common in native applications that pin to keys as well.