If you pin keys you can even pin a key you haven't and never plan to use, keeping the corresponding private key in the company safe as a hedge against something going badly wrong.
If you pin keys you can even pin a key you haven't and never plan to use, keeping the corresponding private key in the company safe as a hedge against something going badly wrong.
It's very easy to avoid the pitfall you mentioned by having multiple valid certs with different expiry dates. You can easily use multiple CAs.
Done your way, a single leaked private key means your entire site is compromised indefinitely. That's unacceptable to me.
As long as the private key is stored/handled safely and RSA/ECC is not broken, it is not vulnerable.
I do agree that key rotation is better/recommended practice.
> a single leaked private key means your entire site is compromised
The leak is the actual vulnerability. As long as the leak is still there and you are not aware of the compromised private key, a fresh new private key will probably leak again.
However, the chances of leaking may be greater if a private key has to be used in multiple locations.