Dumb question: Can you extract the private certificate and use it elsewhere, or is it held securely and only accessible via specific AWS services?
That said, SSL certs and domain renewals are the least interesting but high importance items of running an online business. As I'm already heavily deployed on AWS, I have no problem having them handle all of this for me, for what is free to me. (yes yes, not technically free)
http://security.stackexchange.com/questions/16085/how-to-get...
If a third party controls your keys, certificate pinning is useless to prevent against attacks from that third party or governmental agencies.
Not sure if this approach is common in native applications that pin to keys as well.