> Using the same key pair for multiple certificates is necessary for public key pinning, since Let's Encrypt only issues certificates that last 90 days.
So do like Github does (did?)[0], and make the pins valid for 5 minutes.
[0] looks like they upped it to 60 days?