Generate from your letsencrypt certs.
HKPK (RFC7469) is a standard that tells browser to cache a certain TLS certificate’s signature, and validate that future visits use that certificate. Please read Extended Info as losing your pins may result in migraines (if you use your leaf) You can check or generate your hashes with this tool
letsencrypt
renews your certificates every few months, so if you pin against your cert.pem
and it changes (or you lose it), the browser will still expect to see the old one.