Cert checksum changes all the time when renewing. A feature to trust public key checksum will be good to enable "pinning" when CSR is re-signed without lose trust.
Maybe this can combine for 2068 as a new function which only use SHA256 checksum for trustet public keys.