If my company's server leaf certificate expires and they are creating new certificate with different new Public key as per CA and its policies.
Hence I can only pin certificate rather than public key or SPKI ?
Doing so i know i have to update the new certificate in app and push to users but it won't work for old version users. Any suggestions to avoid this problem?