3 ms·
If you continue to use the same public key, your existing pin will work with your new certificate. So there's nothing to do. IIRC, many (all?) LE clients genera
by ivanr 9y ago
If you continue to use the same public key, your existing pin will work with your new certificate. So there's nothing to do. IIRC, many (all?) LE clients generate new keys by default, so this is something you need to plan for in advance.
If you want to change your public key, you have to obtain your certificate in advance, then introduce its pin into your HPKP configuration at least N days before the certificate switch. In this case, N is your maximum HPKP policy duration. With this process you ensure that, when you do switch the certificates, all your users will have the correct pin for it. Whatever HPKP policy you had N+1 days prior, it will have expired by then. You probably want some additional safety margin there too.