If you're in a position to pin certs, aren't you in a position to ignore normal CAs and just keep doing that?