Certificate pinning trades flexibility for tighter expectations

Pinning means an application refuses to accept any certificate except the specific one it expects.

It defeats an attacker who has obtained a fraudulent but otherwise valid certificate, which is its purpose. It also means that when the legitimate certificate changes, every client breaks until updated. Several well-known outages came from pinning, and it remains the right answer in narrow cases where the client can be updated in step.

More on TLS and PKI