Rate limit or certificate limit?

It's clearly defined what pending is. It's a little ambiguous, because it doesn't say if invalid attempts count, too.

How did you do that? Did you save all the tokens and challenge URIs?