I feel stupid having to ask this question, but is a backup key literally just a different SSL certificate issued by the same or another CA for the same domain(s)? You keep it on standby in case your primary certificate is compromised? Do I use the same CSR and private key or do I generate new ones?<p>EDIT: Okay, the coffee is flowing and the gears are starting to turn. I guess if I'm going to pin my cert, I should generate a new private key for the backup, and if I'm going to pin the intermediate cert, I should use a different CA. And for maximum protection, do both, and not keep both private keys on the same servers. Does that make sense?